Unicode和html的关系
http://en.wikipedia.org/wiki/Unicode_and_HTML
什么是HTTPOnly
http://www.owasp.org/index.php/HTTPOnly
J2EE中和安全相关的代码
http://www.owasp.org/index.php/Searching_for_Code_in_J2EE/Java
XSS
http://www.owasp.org/index.php/XSS
http://antixss.codeplex.com/SourceControl/list/changesets
DOM_Based_XSS
http://www.owasp.org/index.php/DOM_Based_XSS
浏览器安全
http://code.google.com/p/browsersec/wiki/Part2