Due to the Internet’s quick development, web apps are now widely used in contemporary culture. Web apps are a common target for hackers because they are often used for social networks, media, administration, etc., and often include a lot of private user data. Cross-site scripting, or XSS, attacks have grown to be one of the main security threats to web applications. Malicious script codes are widely used by attackers to hijack victims’ browser cookies and collect hidden backstage login credentials, which allows them to steal users’ private online data or access websites they are not authorized to access. In addition, among other extremely dangerous and destructive things, the attacker can employ XSS to obtain the victim’s phone number, IP address, virtual identities, operating system, browser, and order information from online stores. Many solutions that automate the testing of web applications for Cross-Site Scripting (XSS) vulnerabilities perform better when the user has strong subject-matter knowledge. They rely on brute force techniques, though, which aren’t always the greatest choice. Competent penetration testers, on the other hand, employ more accurate but often unorganized exploit strategies. This work aims to compare and assess earlier approaches for XSS attack mitigation, prediction, and detection.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detection, Prevention, and Mitigation of Cross Site Scripting Attacks

  • G. Gautam,
  • E. Rajesh,
  • M. D. Laxmi Narayan,
  • K. Jayakumar

摘要

Due to the Internet’s quick development, web apps are now widely used in contemporary culture. Web apps are a common target for hackers because they are often used for social networks, media, administration, etc., and often include a lot of private user data. Cross-site scripting, or XSS, attacks have grown to be one of the main security threats to web applications. Malicious script codes are widely used by attackers to hijack victims’ browser cookies and collect hidden backstage login credentials, which allows them to steal users’ private online data or access websites they are not authorized to access. In addition, among other extremely dangerous and destructive things, the attacker can employ XSS to obtain the victim’s phone number, IP address, virtual identities, operating system, browser, and order information from online stores. Many solutions that automate the testing of web applications for Cross-Site Scripting (XSS) vulnerabilities perform better when the user has strong subject-matter knowledge. They rely on brute force techniques, though, which aren’t always the greatest choice. Competent penetration testers, on the other hand, employ more accurate but often unorganized exploit strategies. This work aims to compare and assess earlier approaches for XSS attack mitigation, prediction, and detection.