摘要
路由设备的脚本攻击研究在国内还处于早期阶段,随着国内路由设备的普及,它潜在的安全影响越来越受到关注。阐述用户浏览器提交数据的详细过程,以及整个过程存在的脚本攻击威胁,并通过具体的方法完成路由设备的远程攻击、建立跨域漏洞攻击模型。
Cross-site-scripting on network device in China is still at an early stage, with the popularization of routing equipment, its potential secu-rity problems are increasingly concerned. Analyzes the detailed process of the user submit data by browser, shows the whole script attack process, through the concrete method to complete the remote attack of the equipment, establishes the cross-domain attack model.