首页> 外文期刊>Asian Journal of Information Technology >Preventing Cross Site Scripting Attacks in Websites
【24h】

Preventing Cross Site Scripting Attacks in Websites

机译:防止网站中的跨站点脚本攻击

获取原文
       

摘要

Cross-Site Scripting attacks (XSS) is one type of the computer security breaches that attacker uses web application to inject his malicious code. It enables attacker to inject scripting code that executes in the browser and view by other users where attacker steal cookies from account of users and access the sensitive information in the web application. In this attack, the malicious scripting is injected that may make the website under the control of attacker. There are solutions to these attacks on the levels of client-side and server-side which can complete each other?s to provide protection for the website and web applications to prevent malicious scripts from being implemented. In this study, we clearly show and simulate how the cross site scripting disturbs the website and how to put method to prevent this vulnerability. Stored XSS attacks and Reflected XSS attacks are prevented using the encoding and filtering input. The proposed method is tested in many web site in client side and server side.
机译:跨站点脚本攻击(XSS)是攻击者使用Web应用程序注入其恶意代码的一种计算机安全漏洞。它使攻击者能够注入在浏览器中执行的脚本代码,并由其他用户查看,其中攻击者从用户帐户窃取Cookie并访问Web应用程序中的敏感信息。在这种攻击中,注入了恶意脚本,可能使网站受到攻击者的控制。在客户端和服务器端的级别上有针对这些攻击的解决方案,这些解决方案可以相互完成,从而为网站和Web应用程序提供保护,以防止实施恶意脚本。在本研究中,我们清楚地显示和模拟跨站点脚本如何干扰网站以及如何放置方法来防止此漏洞。使用编码和过滤输入可防止存储的XSS攻击和Reflected XSS攻击。所提出的方法已经在客户端和服务器端的许多网站中进行了测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号