官术网_书友最值得收藏!

Unsanitized Data – An XSS Case Study

Cross-Site Scripting (XSS) is a vulnerability caused by exceptions built into the browser's same-origin policy restricting how assets (images, style sheets, and JavaScript) are loaded from external sources.

Consistently appearing in the OWASP Top-10 survey of web-application vulnerabilities, XSS has the potential to be a very damaging, persistent exploit that affects large sections of the target site's user base. It can also be difficult to stamp out, especially in sites that have large attack surfaces, with many form inputs, logins, discussion threads, and so on, to secure.

This chapter will cover the browser mechanisms that create the opportunity for XSS, the different varieties of XSS (persistent, reflected, DOM-based, and so on), how to test for it, and a full example of an XSS vulnerability  from discovering the bug to submitting a report about it.

The following topics will be covered in this chapter:

  • Overview of XSS
  • Testing for XSS
  • An end-to-end example of XSS

主站蜘蛛池模板: 德保县| 达日县| 淮滨县| 英山县| 黑河市| 邢台市| 西藏| 东乡族自治县| 托里县| 华安县| 清丰县| 和林格尔县| 塔河县| 惠东县| 彰化市| 固安县| 博爱县| 北辰区| 天等县| 孙吴县| 沈丘县| 随州市| 改则县| 屏边| 伊春市| 盐城市| 广丰县| 三原县| 密云县| 茶陵县| 宣恩县| 泾阳县| 松潘县| 石泉县| 增城市| 华蓥市| 达州市| 乌兰浩特市| 水富县| 辰溪县| 西藏|