...
首页> 外文期刊>Procedia Computer Science >Automated Discovery of JavaScript Code Injection Attacks in PHP Web Applications
【24h】

Automated Discovery of JavaScript Code Injection Attacks in PHP Web Applications

机译:在PHP Web应用程序中自动发现JavaScript代码注入攻击

获取原文
   

获取外文期刊封面封底 >>

       

摘要

This paper discussed some of the performance issues in the existing defensive solutions of Java Script injection attacks (e.g. Cross-Site Scripting (XSS) attacks). Moreover, a high level of comparison for such existing solutions has been done based on some useful metrics. Based on the identified performance issues, this paper proposed an automated detection system, which scans the numerous possible locations of web sites for JavaScript injection vulnerabilities. Our detection system, firstly, scans the web site for discovering the injection locations. Secondly, it injects the malicious XSS attack vectors in such injection points. Lastly, it takes an input as the list of different XSS attacks exploited in the second step and scan for these attacks in the vulnerable web application. Detection capability of our automated system is evaluated on a real world PHP web application i.e. BlogIt and results obtained are very promising.
机译:本文讨论了Java Script注入攻击的现有防御解决方案(例如跨站脚本(XSS)攻击)中的一些性能问题。此外,已经基于一些有用的指标对此类现有解决方案进行了高水平的比较。基于发现的性能问题,本文提出了一种自动检测系统,该系统可以扫描网站的许多可能位置以查找JavaScript注入漏洞。我们的检测系统首先会扫描网站以发现注射位置。其次,它将恶意的XSS攻击媒介注入这些注入点。最后,它将输入作为第二步中利用的不同XSS攻击的列表,并在易受攻击的Web应用程序中扫描这些攻击。我们的自动化系统的检测能力是在真实世界的PHP Web应用程序(即BlogIt)上评估的,所获得的结果非常有希望。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号