期刊文献+

跨站脚本XSS安全漏洞 被引量:4

下载PDF
导出
摘要 跨站脚本Cross-Site Scripting(XSS)是最为流行的Web安全漏洞之一。那么,什么是跨站脚本?它有什么危害?Web开发人员又如何在开发过程中避免这类安全漏洞?这都是本文要重点解决的问题。
作者 褚诚云
出处 《程序员》 2008年第11期97-99,共3页 Programmer
  • 相关文献

参考文献5

  • 1.Cross-site scripting[]..
  • 2.How To:Prevent Cross-Site Scripting in ASP.NET[]..
  • 3How To:Protect From Injection Attacks in ASP.NET. http://msdn.microsoft.com/en-au/library/bb355989. aspx .
  • 4Microsoft Anti-Cross Site Scripting Library V1.5: Protecting the Contoso Bookmark Page. http:// msdn,microsoft.com/en-us/library/aa973813.aspx .
  • 5Mitigating Cross-site Scripting With HTTP-only Cookies. http://msdn.microsoft.com/en-us/library/ ms533046.aspx .

同被引文献17

  • 1Johns M, Engelmann B, Posegga J. XSSDS: server-side detection of cross-site scripting attacks[C-I,//Proceedings of Computer Security Applications Conference. IS. 1. ] : IEEE, 2008..335 - 344.
  • 2Klein A. DOM based cross site scripting or XSS of the third kind[-JT. Web Application Security Consortium, 2005,4:59 - 64.
  • 3Jovanovic N, Kruegel C, Kirda E. Pixy.. a static analysis tool for detecting Web application vulnerabilities [J-]. IEEE, 2006,126..258-263.
  • 4Artzi S, Kiezun A, Dolby J, et al. Finding bugs in dynamic web applications E C ff Proceedings of the 2008 International Symposium on Software Testing and Analysis. [-S. 1. 1: ACM, 2008:261 -272.
  • 5Vogt P, Nentwich F, Jovanovic N, et al. Cross site scripting prevention with dynamic data tainting and static analysis[C]//Proceedings of the Network and Dis- tributed System Security Symposium (NDSS). New York, USA..[s. n. ], 2007..95 - 102.
  • 6Tang Zhushou, Zhu Haojin, Cao Zhenfu, et al. LWMxD: lexical based webmail XSS discoverer[,C] ff Proceedings of the First International Workshop on Security in Computers, Networking and Commu- nications. [-S. 1. ] : IEEE, 2008:976 - 981.
  • 7Ismail O, Etoh M, Kadobayashi Y. A proposal and implementation of automatic detection/collection system for cross-site scripting vulnerability [-C3 // Proceedings of the 18th International Conference on Advanced Information Networking and Applications. Washington, D.C. , USA: IEEE. 2004,129 - 136.
  • 8OWASP. The Ten Most Critical Web Application Security Risks[R].http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf,2012.
  • 9W3school.ASP Request 对象.
  • 10瑞星网.Web攻防系列教程之Cookie注入攻防实战.

引证文献4

二级引证文献16

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部