官术网_书友最值得收藏!

Unsanitized Data – An XSS Case Study

Cross-Site Scripting (XSS) is a vulnerability caused by exceptions built into the browser's same-origin policy restricting how assets (images, style sheets, and JavaScript) are loaded from external sources.

Consistently appearing in the OWASP Top-10 survey of web-application vulnerabilities, XSS has the potential to be a very damaging, persistent exploit that affects large sections of the target site's user base. It can also be difficult to stamp out, especially in sites that have large attack surfaces, with many form inputs, logins, discussion threads, and so on, to secure.

This chapter will cover the browser mechanisms that create the opportunity for XSS, the different varieties of XSS (persistent, reflected, DOM-based, and so on), how to test for it, and a full example of an XSS vulnerability  from discovering the bug to submitting a report about it.

The following topics will be covered in this chapter:

  • Overview of XSS
  • Testing for XSS
  • An end-to-end example of XSS

主站蜘蛛池模板: 拜泉县| 崇义县| 白沙| 云浮市| 靖州| 天长市| 泰宁县| 资阳市| 洛南县| 太保市| 两当县| 甘谷县| 宜良县| 应城市| 顺昌县| 庆元县| 全椒县| 赤水市| 沅陵县| 乌兰察布市| 栖霞市| 五台县| 旬阳县| 武陟县| 巴林右旗| 定襄县| 伊川县| 台北市| 金坛市| 慈利县| 贡嘎县| 微博| 白河县| 哈巴河县| 余干县| 镇安县| 延庆县| 苍南县| 四会市| 贵德县| 镇赉县|