Automatic and Context-Aware Cross-Site Scripting Filter Evasion
Cross-Site Scripting (XSS) is a pervasive vulnerability that involves a huge portion of modern web applications. Implementing a correct and complete XSS filter for user-generated content can really be a challenge for web developers. Many aspects have to be taken into account sincethe attackers may continuously show off a potentially unlimited armory. This work proposes an approach and a tool – named snuck – for web application penetration testing, which can definitely help in finding hard-to-spot and advanced XSS vulnerabilities. This methodology is based on the inspection of the inject ion’s reflection context and relies on a set of specialized and obfuscated attack vectors for bypassing filter based protections, adopted against potentially harmful inputs. In addition, XSS testing is performed in-browser, this means that a web browser is driven in reproducing the attacker and possibly the victim behavior. Results of several tests on many popular Content Management Systems proved the benefits of this approach: no other web vulnerability scanner would have been able to discover some advanced ways to bypass robust XSS filters.
Year of publication: |
2012-04
|
---|---|
Authors: | d’Amore, Fabrizio ; Gentile, Mauro |
Institutions: | Dipartimento di Ingegneria Informatica, Automatica e Gestionale "Antonio Ruberti", Facoltà di Ingegneria dell'Informazione Informatica e Statistica |
Subject: | Computer security | Network Security | Web Application Security | Browser Security | Vulnerability Detection | Cross-site Scripting | XSS |
Saved in:
Extent: | application/pdf |
---|---|
Series: | DIAG Technical Reports. - ISSN 2281-4299. |
Type of publication: | Book / Working Paper |
Notes: | Number 2012-04 58 pages |
Source: |
Persistent link: https://www.econbiz.de/10010595362
Saved in favorites
Similar items by subject
-
Global research productivity in cybersecurity: a scientometric study
Loan, Fayaz Ahmad, (2021)
-
Computer Network Security and Cyber Ethics (4th ed.)
(2015)
-
Cybersecurity : Technology and Governance
Jøsang, Audun, (2025)
- More ...