基于反过滤规则集和自动爬虫的 XSS漏洞深度挖掘技术

Technique for Deep Discovering XSS Vulnerability Based on Anti-Filter Rules Set and Automatic Crawler Program

  • 摘要: 为解决Web网站跨站脚本攻击(XSS)问题,通过对XSS漏洞特征及过滤方式的分析,提出了通过反过滤规则集转换XSS代码并用自动爬虫程序实现漏洞代码的自动注入和可用性检验的XSS漏洞挖掘技术,依此方法可以获取XSS漏洞代码的转换形式及漏洞的注入入口,以实现对Web跨站漏洞深度挖掘. 提出的XSS漏洞挖掘技术在邮箱XSS漏洞挖掘及Web网站XSS漏洞检测方面的实际应用验证了该技术的有效性.

     

    Abstract: To guard against the WEB site's cross-site scripting (XSS) attacks, the characteristics and filtering mode of XSS vulnerabilities were analyzed. A technical scheme for XSS vulnerabilities discovery was presented. First, an anti-filter rules set was used to convert the XSS code and then an automatic crawler program was employed to inject the XSS code and test it's usability. Finally, the effective XSS code and the point of the injected code could be acquired. The presented method has been successfully used to discover the XSS vulnerabilities of web-email and web site.

     

/

返回文章
返回
Baidu
map