XSS Attacks: Cross Site Scripting Exploits and Defense

XSS Attacks: Cross Site Scripting Exploits and Defense
复制标题

DOI:
--
复制
发表时间:
2007-05
期刊:
--
影响因子:
--
通讯作者:
Seth Fogie;Jeremiah Grossman;Robert “RSnake” Hansen;Anton Rager;P. Petkov
Seth Fogie;Jeremiah Grossman;Robert “RSnake” Hansen;Anton Rager;P. Petkov
中科院分区:
其他
文献类型:
--
作者:
Seth Fogie;Jeremiah Grossman;Robert “RSnake” Hansen;Anton Rager;P. Petkov

文献摘要

被引文献

相似文献

跨站脚本攻击首先要定义术语并奠定基础。它假设读者熟悉基本的 Web 编程 (HTML) 和 JavaScript。首先,它讨论了使 XSS 成为有效问题的概念、方法和技术。然后介绍各种类型的 XSS 攻击以及它们的实施、使用和滥用方式。在彻底探讨了 XSS 后,下一部分提供了 XSS 恶意软件示例,并演示了 XSS 是一种危险风险的真实案例,它使互联网用户面临远程访问、敏感数据盗窃和金钱损失。最后,本书最后探讨了开发人员如何避免 Web 应用程序中的 XSS 漏洞,以及用户如何避免成为受害者。受众是 Web 开发人员、安全从业者和管理人员。 *XSS 漏洞存在于十分之八的网站中 *本书的作者是无可争议的行业领先权威 *包含在其他任何地方都找不到的独立、前沿的研究、代码列表和漏洞利用
Cross Site Scripting Attacks starts by defining the terms and laying out the ground work. It assumes that the reader is familiar with basic web programming (HTML) and JavaScript. First it discusses the concepts, methodology, and technology that makes XSS a valid concern. It then moves into the various types of XSS attacks, how they are implemented, used, and abused. After XSS is thoroughly explored, the next part provides examples of XSS malware and demonstrates real cases where XSS is a dangerous risk that exposes internet users to remote access, sensitive data theft, and monetary losses. Finally, the book closes by examining the ways developers can avoid XSS vulnerabilities in their web applications, and how users can avoid becoming a victim. The audience is web developers, security practitioners, and managers. *XSS Vulnerabilities exist in 8 out of 10 Web sites *The authors of this book are the undisputed industry leading authorities *Contains independent, bleeding edge research, code listings and exploits that can not be found anywhere else