-
252
pages
-
English
-
Documents
-
2011
Description
Dissertationzur Erlangung des akademischen Grades einesDoktors der NaturwissenschaftenCode Injection Vulnerabilities in WebApplications - Exemplified at Cross-siteScriptingMartin JohnsEingereicht an der Fakult¨at fur¨ Informatik und Mathematik der Universit¨at PassauGutachter: Prof. Dr. Joachim PoseggaProf. Dr. Dieter GollmannSubmitted April 14th 2009, defended July 22nd 20092AbstractThe majority of all security problems in today’s Web applications is caused by string-based code injection, with Cross-site Scripting (XSS) being the dominant representativeof this vulnerability class. This thesis discusses XSS and suggests defense mechanisms.We do so in three stages:First, we conduct a thorough analysis of JavaScript’s capabilities and explain howthese capabilities are utilized in XSS attacks. We subsequently design a systematic,hierarchical classification of XSS payloads. In addition, we present a comprehensive sur-vey of publicly documented XSS payloads which is structured according to our proposedclassification scheme.Secondly, we explore defensive mechanisms which dynamically prevent the executionof some payload types without eliminating the actual vulnerability. More specifically,we discuss the design and implementation of countermeasures against the XSS payloads“Session Hijacking”, “Cross-site Request Forgery”, and attacks that target intranet re-sources.
-
Publié par
-
Publié le
01 janvier 2011
-
Langue
English
-
Poids de l'ouvrage
6 Mo