摘要
客户端脚本植入攻击是近年来攻击者常用的一种攻击手段,给Web应用程序带来了相当大的安全隐患。介绍了跨站脚本攻击和网络钓鱼攻击的原理及防御。分析了两种攻击在获取用户信息时的不全面,从而提出了一种针对Web-mail邮箱的跨站网络钓鱼攻击方法。这种攻击方法结合了跨站脚本攻击和网络钓鱼攻击,不仅能够获取用户邮箱的cookie、账号及密码,而且还可以获取用户的个人相关信息。最后,针对提出的攻击方法给出了防御措施。
Client-side script insertion attack is commonly used by the attacker as a means of attack in recent years and has brought enormous potential safety problems to the Web application. This paper gives the theories and defenses of XSS vulnerability and Phishing vulnerability, then it analyzes the inadequacies of these two vulnerabilities in obtaining user information, and thus proposes a XSS Phishing vulnerability method for Web-mail mailbox. This vulnerability, in combination of the cross-site scripting attacks with phishing attacks, could obtain the cookie, account number and password of the user’s Web-mail mailbox while acquire the user’s personal information. Finally, the article discusses the defense measures against the proposed attacks.
出处
《通信技术》
2010年第8期164-166,共3页
Communications Technology
关键词
跨站脚本攻击
网络钓鱼攻击
脚本
钓鱼页面
cross-site scripting attack
Web phishing attack
script
phishing-page