#025 · Security ProfessionalsLegendaryLocked in

Jeremiah Grossman

The Web Application Security Authority

XSS Attacks, WhiteHat Security, and making web appsec a discipline

Rating

90Impact score
Technical depth90
Defensive craft94
Research93
Influence93
FromUSA
Era1999–present

Domains

Web application securityCross-site scriptingVulnerability data

Scouting report

Was an information security officer at Yahoo before founding WhiteHat Security in 2001, where continuous scanning of thousands of production sites produced the first credible public statistics on how long real web vulnerabilities actually stay open. Co-founded the Web Application Security Consortium, and co-authored XSS Attacks: Cross Site Scripting Exploits and Defense in 2007 — the book that turned cross-site scripting from a curiosity into a class of bug developers were expected to know.

Curator’s note

The XSS book is still the reference. Web appsec became a discipline on his watch.

Portrait

Painted from a photograph of Jeremiah Grossman by Jeremiah Grossman, supplied by the subject.