XSS Attacks: Cross Site Scripting Exploits and Defense

Cover
Syngress, 23.05.2007 - 448 Seiten
A cross site scripting attack is a very specific type of attack on a web application. It is used by hackers to mimic real sites and fool people into providing personal data.

XSS Attacks starts by defining the terms and laying out the ground work. It assumes that the reader is familiar with basic web programming (HTML) and JavaScript. First it discusses the concepts, methodology, and technology that makes XSS a valid concern. It then moves into the various types of XSS attacks, how they are implemented, used, and abused. After XSS is thoroughly explored, the next part provides examples of XSS malware and demonstrates real cases where XSS is a dangerous risk that exposes internet users to remote access, sensitive data theft, and monetary losses. Finally, the book closes by examining the ways developers can avoid XSS vulnerabilities in their web applications, and how users can avoid becoming a victim. The audience is web developers, security practitioners, and managers.

  • XSS Vulnerabilities exist in 8 out of 10 Web sites
  • The authors of this book are the undisputed industry leading authorities
  • Contains independent, bleeding edge research, code listings and exploits that can not be found anywhere else
 

Inhalt

Chapter 2 The XSS Discovery Toolkit
15
Chapter 3 XSS Theory
67
Chapter 4 XSS Attack Methods
163
Chapter 5 Advanced XSS Attack Vectors
191
Chapter 6 XSS Exploited
219
Chapter 7 Exploit Frameworks
293
Chapter 8 XSS Worms
375
Chapter 9 Preventing XSS Attacks
395
Appendix A The Owned List
409
Index
439
Urheberrecht

Andere Ausgaben - Alle anzeigen

Häufige Begriffe und Wortgruppen

Autoren-Profil (2007)

Jeremiah Grossman, founder and chief technology officer of WhiteHat Security, is a world-renowned expert in web application security and a founding member of the Web Application Security Consortium (WASC). At WhiteHat, Mr. Grossman is responsible for web application security R&D and industry evangelism. He is a frequent speaker at industry events including the Black Hat Briefings, ISACA, OWASP, NASA, ISSA and Defcon. A trusted media resource, Mr. Grossman has been featured in USA Today, the Washington Post, Information Week, NBC Nightly News, and many others. Prior to WhiteHat, Mr. Grossman was an information security officer at Yahoo!

Bibliografische Informationen