Hi! I'm using BlackICE PC Protection (formerly known as BlackICE Defender) for a very long time[1, 2]. It is one of my favorite hostbased intrusion detection systems and personal firewall for windows. During some tests for a paper on cross site scripting I've seen that there is an evasion possibility in BlackICE PC Protection. If I'm realizing such an request with a GET or POST method, the cross site scripting is possible but I get an alert[3]: > [Unauthorized Access Attempt] This signature detects if an HTTP GET > request contains a 'script' tag. It seems that BlackICE PC Protection doesn't check a HEAD, PUT, DELETE, and TRACE request for the