You can read over at F-Secure the story of Netscape.com from a few days ago. Not withstanding the fact that the new Netscape.com is a blatant rip-off of Digg, it was kind of funny to see the fact that a company with as strong a perceived brand as Netscape making the rookie mistake of not preventing XSS from being stopped in user comments.

Just a few days earlier, Myspace was attacked by the Flash worm, which spread thanks to XSS and a vulnerability in the ubiquitous Macromedia/Adobe Flash Player.

To all you web developers: wake up! XSS is a serious threat. The combination of the Web 2.0 style sites—where everyone is creating content—and the threats of phishing and/or destructive viruses should be enough to concern everyone. Personally, I’m getting tired of posting about this.