期刊文献+

基于动态数据生成缺陷的XSS漏洞挖掘技术 被引量:3

Exploiting XSS Vulnerability based on Dynamic Data Generating Flaw
下载PDF
导出
摘要 XSS漏洞普遍存在于当前Web应用中,而且危害极其严重。随着Web2.0的到来,Web应用日趋大型化和复杂化,进一步为Web漏洞的滋生提供了温床。针对大型Web应用中复杂的数据组织结构,文章提出一种基于动态数据生成缺陷的XSS漏洞挖掘方法,能快速、高效地挖掘出大型Web应用中存在的XSS漏洞。同时,利用这一挖掘方法对Web应用中存在的HTTP Response Splitting漏洞、URL Redirection漏洞进行挖掘分析,都取得了非常显著的效果。 XSS is the most common and seriously harmful vulnerability in current Web applications. With the arrival of Web2.0 technologies, Web applications tend to be much larger and more complex, which provided the hotbed for Web vulnerabilities. According to the complex structure of data organization in large-scale web applications, in this paper we proposed an approach for exploiting XSS vulnerability based on dynamic data generating flaw. It can exploit XSS vulnerability existing in large-scale Web applications quickly and effectively. We also use this method to analysis HTTP Response Splitting vulnerability and URL Redirection vulnerability in Web applications and also achieved significant results.
出处 《信息网络安全》 2012年第11期44-47,共4页 Netinfo Security
基金 国家自然科学基金资助项目[61170268 61272493]
关键词 跨站脚本 HTTP Response SPLITTING URL REDIRECTION cross-site scripting HTTP response splitting URL redirection
  • 相关文献

参考文献14

  • 1Web 2.0[EB/OL]. http://en.wikipedia.org/wiki/Web_2.0, 2012-08-29.
  • 2Web vulnerabilities[EB/OL], http://www.acunetix.com/vulnevabilities.
  • 3Aelphaeis Mangarae. XSS Attacks FAQ[EB/OL]. http://www, infosecwriters.com/text_resources/pdf/XSS_Attack_FAQ.pdf.
  • 4PaPPy. How to write a XSS(cross site scripting) worm for McCodes sites{EB/OL], http://www.milworm.com/paper/272, 2009-01-19.
  • 5599eme Man. Xss & lffame Phishing[EB/OL]. http://www.exploit- db.com/wp-content/thenes/exploit/docs/356.pdf, 2012-08-29.
  • 6Mastah yeti. Abusing Password. Managers with XSS.
  • 7Diabolic Crab.HTTP IkESPONSE SPLITTING[EB/OL]. http:// www.infosecwriters.com/text_resources/pdf/HTTP_Response.pdf, 2012-08-29.
  • 8Krishna Bhargrava, l)ougtas Brewer, Kang Li. A Study of URL Redirection Indicating Span[C]. In CEAS 2009.
  • 9Edmond Woychowsky. Ajax Creating Web Pages with Asynchronous JavaScript and XML[M]. Prentice Hall,2006.
  • 10Sang Shin. Introduction to JSON (JavaScript Object Notation)[EB/ OL]. http://www.docin.com/p-8643781 .html,2012-08-29.

同被引文献13

引证文献3

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部