This article first appeared on the Firefox Attack & Defense blog. Despite alltheefforts of fixing Cross-Site Scripting (XSS) on the web, it continuously ranks as one of the most dangerous security issues in software. In particular, DOM-based XSS is gaining increasing relevance: DOM-based XSS is a form of XSS …