摘要
Web应用程序下XSS漏洞分为存储式漏洞、反射式漏洞及基于DOM的漏洞,主要攻击方式为CSRF攻击、窃取Cookie会话和客户端代理攻击.从服务器端和客户端两个角度提出了XSS漏洞的防御措施,为开发人员及用户提供安全防范经验.
The web-based XSS vulnerabilities are usually in the form of storages,reflections and DOM bases,that are viable to the CSRF attacks, theft of the cookie sessions and client proxy attacks. This paper provides with the measures against XSS vulnerabilities for servers and clients.
出处
《石家庄职业技术学院学报》
2012年第6期41-43,共3页
Journal of Shijiazhuang College of Applied Technology