首页> 外文会议>International Conference on Computational Science and Computational Intelligence >Large-Scale Detection of DOM-Based XSS Based on Publisher and Subscriber Model
【24h】

Large-Scale Detection of DOM-Based XSS Based on Publisher and Subscriber Model

机译:基于发布者和订阅者模型的基于DOM的XSS的大规模检测

获取原文

摘要

Cross-site scripting (also referred to as XSS) is a vulnerability that allows an attacker to send malicious code (usually in the form of JavaScript) to another user. XSS is one of the top 10 vulnerabilities on Web application. While a traditional cross-site scripting vulnerability exploits server-side codes, DOM-based XSS is a type of vulnerability which affects the script code being executed in the clients browser. DOM-based XSS vulnerabilities are much harder to be detected than classic XSS vulnerabilities because they reside on the script codes from Web sites. An automated scanner needs to be able to execute the script code without errors and to monitor the execution of this code to detect such vulnerabilities. In this paper, we introduce a distributed scanning tool for crawling modern Web applications on a large scale and detecting, validating DOMbased XSS vulnerabilities. Very few Web vulnerability scanners can really accomplish this.
机译:跨站点脚本(也称为XSS)是一个漏洞,它使攻击者可以将恶意代码(通常以JavaScript的形式)发送给另一个用户。 XSS是Web应用程序上十大漏洞之一。传统的跨站点脚本漏洞利用服务器端代码,而基于DOM的XSS是一种漏洞,会影响在客户端浏览器中执行的脚本代码。与传统的XSS漏洞相比,基于DOM的XSS漏洞要难得多,因为它们位于网站的脚本代码中。自动扫描程序需要能够正确执行脚本代码并监视此代码的执行以检测此类漏洞。在本文中,我们介绍了一种分布式扫描工具,可用于大规模爬网现代Web应用程序并检测,验证基于DOM的XSS漏洞。很少有Web漏洞扫描程序能够真正做到这一点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号