官术网_书友最值得收藏!

Unsanitized Data – An XSS Case Study

Cross-Site Scripting (XSS) is a vulnerability caused by exceptions built into the browser's same-origin policy restricting how assets (images, style sheets, and JavaScript) are loaded from external sources.

Consistently appearing in the OWASP Top-10 survey of web-application vulnerabilities, XSS has the potential to be a very damaging, persistent exploit that affects large sections of the target site's user base. It can also be difficult to stamp out, especially in sites that have large attack surfaces, with many form inputs, logins, discussion threads, and so on, to secure.

This chapter will cover the browser mechanisms that create the opportunity for XSS, the different varieties of XSS (persistent, reflected, DOM-based, and so on), how to test for it, and a full example of an XSS vulnerability  from discovering the bug to submitting a report about it.

The following topics will be covered in this chapter:

  • Overview of XSS
  • Testing for XSS
  • An end-to-end example of XSS

主站蜘蛛池模板: 长丰县| 阿合奇县| 栖霞市| 三门县| 稻城县| 泸水县| 五指山市| 会泽县| 昌乐县| 瑞安市| 尚志市| 东安县| 奇台县| 商洛市| 伊宁市| 青岛市| 高台县| 台湾省| 连山| 福泉市| 威信县| 崇仁县| 乌兰县| 郯城县| 牙克石市| 寿宁县| 雅江县| 朔州市| 洛阳市| 定南县| 岢岚县| 砀山县| 堆龙德庆县| 响水县| 台中市| 哈巴河县| 邵武市| 乌鲁木齐县| 高要市| 石河子市| 河东区|