|
発表題目:An Automatic Detection/Collection System for Cross-Site
Scripting Vulnerability
発表概要:
Cross-Site Scripting (XSS) vulnerability is caused by failure of Web
applications to properly validate user input before returning it to
the client's Web browser. Although several approaches exist for defending
against XSS attacks, XSS vulnerabilities continue to appear in Web applications.
These weaknesses, which often result from poorly developed Web applications and
data processing systems, allows attackers to embed malicious HTML-based
contents, such as JavaScripts, within client HTTP requests. Through embedding
HTML code and scripting elements, it is possible to steal session ID
information, thus resulting in the leakage of confidential information. I
propose a system that automatically detects XSS vulnerability by manipulating
either a request or a server response at the client side. The system also
shares the collected vulnerability information via a central reposotory. My
approach is quite different from other work in the literature, wich only
protects users from XSS attacks, but also detects Web servers with XSS
vulnerabilities.
|