发明名称 Automated detection of cross site scripting vulnerabilities
摘要 An automated method and system for testing a web site for vulnerability to a cross site scripting (XSS) attack are disclosed. The automated tool injects a tracer value into both GET and POST form data, and monitors the resultant HTML to determine whether the tracer value is returned to the local machine by the server to which it was sent. If the tracer value is returned, the automated tool attempts to exploit the web site by injecting a non-malicious script as part of an input value for some form data, based on the location in the returned HTML in which the returned tracer value was found. If the exploit is successful, as indicated by the non-malicious script, the automated tool logs the exploit to a log file that a user can review at a later time, e.g., to assist in debugging the web site.
申请公布号 EP1420562(A2) 申请公布日期 2004.05.19
申请号 EP20030023125 申请日期 2003.10.10
申请人 MICROSOFT CORPORATION 发明人 GALLAGHER, THOMAS
分类号 G06F21/20;G06F21/00;H04L29/06;H04L29/08;(IPC1-7):H04L29/06 主分类号 G06F21/20
代理机构 代理人
主权项
地址