Cross-Site Scripting

Source: Internet
Author: User

Monk who eats wine

Today we will talk about Cross-Site Scripting (XSS). The difference lies in CSS (Cascading Style Sheet .) This is also a security vulnerability. Its impact is related to insecure coding in WEB programs and insecure output variables.

This vulnerability allows attackers to inject code into WEB programs to affect access to user forms, which is usually used in phishing (this is a clear objective J ).

In fact, on websites with vulnerabilities, it is possible to allow the execution of HTML and JavaScript code on an Insecure code, so how to combine it is truly dangerous. This may be to steal cookies or redirect a WEB page to a counterfeit website, and create a login form to steal the user's account and password.

This is usually an underestimating problem for a WEB site administrator, because in fact, XSS cannot compromise on its own active WEB site, however, this can only be used by a naive user.

WEB management takes time to discover such vulnerabilities: At the same time, we can calmly disfrute them; J

 

Ii. XSS type

 

This is called XSS, which is a bit hard to understand because it contains different attack positions and different attack principles.

In fact, there are three types of cross-site, which are commonly named:

<! -- [If! SupportLists] --> n <! -- [Endif] --> DOM-Based XSS

<! -- [If! SupportLists] --> n <! -- [Endif] --> Non-Persistent XSS

<! -- [If! SupportLists] --> n <! -- [Endif] --> Persistent XSS

Let's Go. Let's analyze them one by one!

<! -- [If! SupportLists] --> a) <! -- [Endif] --> Dom-Based XSS

This DOM-based cross-site scripting allows an attacker not to work in the victim's WEBPAGE, but on the victim's machine: different operating systems usually contain pages created by "Since born" for different targets, but only humans make such errors, such HTML pages are often exploited by attackers because of code vulnerabilities.

This method can be used to exploit DOM-based XSS vulnerabilities on users' local machines:

<! -- [If! SupportLists] --> I. <! -- [Endif] --> attackers can create a good and malicious website.

<! -- [If! SupportLists] --> ii. <! -- [Endif] --> enables a naive user to open the site.

<! -- [If! SupportLists] --> iii. <! -- [Endif] --> the user accesses this fragile page on his machine.

<! -- [If! SupportLists] --> iv. <! -- [Endif] --> the attacker's website sends a command on this vulnerable page.

<! -- [If! SupportLists] --> v. <! -- [Endif] --> on the local fragile page, the command is executed through the user privilege.

<! -- [If! SupportLists] --> vi. <! -- [Endif] --> attackers can easily gain control of the victim's computer.

As you think, this simple operation is just standing on a completely new point of weakness.

No J missing

This type of attack is really dangerous because it strictly operates on the victim system. As long as the user does not view its security problems and will not update it later, this DOM-based XSS will not be lost.

Solution:

To prevent such attacks, you must pay attention to the following two tasks:

<! -- [If! SupportLists] --> a) <! -- [Endif] --> do not access untrusted sites.

<! -- [If! SupportLists] --> B) <! -- [Endif] --> Update your system updates in a timely manner.

B) Non-Persistent XSS

This Non-Persistent XSS is actually the most common vulnerability found on the network.

Generally, it is named "Non-Persistent" because it works on the last HTTP Response of a victim's site: if the data displayed is from the attacker client, the result page is automatically generated by the attacker.

Attackers often provide malicious code and try to execute it on the server to obtain some results from the form.

This vulnerability is the most common application on a search engine WEB site. Attackers can write arbitrary HTML code in the search engine box. If this vulnerability exists on this site, the search result is the result after the HTML code is executed.

If this happens, 99% of search engines can execute arbitrary JavaScript code.

In this example, the normal search style of a WEB site is as follows:

PHP? TEXT = CODETOSERCH "> HTTP: // WWW. EXAMPLE. COM/SERARCH. PHP? TEXT = CODETOSERCH

Try to include some HTML tags in the TEXT variable:

Http://www.example.com/search.php? Text =

If this is a vulnerable WEB site, images on this site will be displayed on the search results page.

Try to write some Javascript code in it:

Alert (document. cookie)Http: // www.example.com/search.php? Text = <script> alert (document. cookie) </s

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.