Skip to content

Pragmatic Application Security

Thoughts on Secure Software Development

  • Home
  • Privacy Policy
  • Secodis GmbH

java

Automating Security Tests – Part 2: Testing for Simple XSS

September 27, 2021June 21, 2014 by Matthias Rohr

In part 1 of this series, I described how we can automatically test if a correct security header is a simple JUnit test. In this part, I will demonstrate how we can use self-made test automation to test even vulnerabilities such as Cross-Site Scripting (XSS). XSS is doubtless one of the most common vulnerabilities for … Read more

Categories Security Test Automation Tags java, XSS

About the Author

Matthias Rohr

Matthias (ISSAP, CISSP, CSSLP) is AppSec Lead at Kühne+Nagel and founder of Secodis. He has been active in the field of Application Security since 2006. He is a co-founder of the German OWASP chapter and a regular speaker at AppSec conferences. Matthias has also contributed to the field through several publications on application and product security. He lives and works in Hamburg, Germany.

LinkedIn
  • April 2025
  • December 2024
  • October 2024
  • June 2024
  • March 2024
  • January 2024
  • November 2023
  • September 2023
  • February 2023
  • January 2023
  • September 2021
  • August 2021
  • January 2020
  • October 2019
  • July 2019
  • January 2018
  • January 2017
  • August 2016
  • July 2016
  • March 2016
  • November 2015
  • October 2015
  • September 2014
  • June 2014
  • April 2014
  • February 2014

Tags

Agile Security DAST DevSecOps IAST java OWASP SAMM Pentests RASP SAST Security Champions Security Culture Security Organization Security Requirements Security Testing SSDLC Test Automation Threat Modeling XSS

Archives

  • April 2025
  • December 2024
  • October 2024
  • June 2024
  • March 2024
  • January 2024
  • November 2023
  • September 2023
  • February 2023
  • January 2023
  • September 2021
  • August 2021
  • January 2020
  • October 2019
  • July 2019
  • January 2018
  • January 2017
  • August 2016
  • July 2016
  • March 2016
  • November 2015
  • October 2015
  • September 2014
  • June 2014
  • April 2014
  • February 2014
© 2025 Pragmatic Application Security • Built with GeneratePress