首页> 外国专利> Script-based XSS vulnerability detection

Script-based XSS vulnerability detection

机译:基于脚本的XSS漏洞检测

摘要

Detection of dynamic URLs that are vulnerable to XSS attacks is described. First, a dynamic URL is crafted by incorporating a piece of test code designed to expose an instance of XSS vulnerabilities. Next, the crafted URL is loaded into a browser, which causes a web page to be generated that may include the piece of test code. If, upon loading the web page into the browser, the piece of test code is executed by the browser and the browser sends a request to a web server as a result, then the URL is reported as XSS vulnerable. Others, the URL is not vulnerable to this instance of XSS attack. The test may be repeated multiple times for different pieces of test code, each piece designed to expose a different instance of XSS vulnerabilities.
机译:描述了容易受到XSS攻击的动态URL的检测。首先,通过结合一段旨在暴露XSS漏洞实例的测试代码来设计动态URL。接下来,将精心制作的URL加载到浏览器中,这将导致生成可能包含测试代码的网页。如果在将网页加载到浏览器中时,测试代码由浏览器执行,并且浏览器将请求发送到Web服务器,结果该URL被报告为XSS易受攻击的。在其他情况下,URL不受此XSS攻击实例的攻击。对于不同的测试代码段,该测试可以重复多次,每段代码都设计为公开不同的XSS漏洞实例。

著录项

  • 公开/公告号US8949990B1

    专利类型

  • 公开/公告日2015-02-03

    原文格式PDF

  • 申请/专利权人 SHENG-CHI HSIEH;JUI-PANG WANG;

    申请/专利号US20070962795

  • 发明设计人 SHENG-CHI HSIEH;JUI-PANG WANG;

    申请日2007-12-21

  • 分类号G06F21/00;

  • 国家 US

  • 入库时间 2022-08-21 15:16:51

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号