PDF] A threat pattern for the cross-site scripting (XSS) attack
Por um escritor misterioso
Descrição
A threat pattern is presented that describes cross-site scripting (XSS) attacks, which describes how the attack is performed, which vulnerabilities it exploits, and how to stop it. We present a threat pattern that describes cross-site scripting (XSS) attacks. In this attack attackers insert scripts in web applications that will lead to misuses in a target web application. Cross-Site Scripting is listed as number three risk on the 2013 OWASP Top 10 list; it is an attack made possible due to the lack of user input validation or output escaping, which allows attackers to inject malicious code. The pattern describes how the attack is performed, which vulnerabilities it exploits, and how to stop it.
Cross site scripting (XSS) attack - Types and Examples
5 Real-World Cross Site Scripting Examples
Cross-Site Scripting (XSS) - X Security Group
Detection of cross-site scripting (XSS) attacks using machine
Apache Security: Chapter 10. Web Application Security
What is Cross-Site Scripting (XSS)? How to Prevent and Fix It
What Is Cross-Site Scripting (XSS), Definition
Study of Cross-Site Scripting Attacks and Their Countermeasures
Testing Cross-Site Scripting