Cross-Site Script Inclusion - A Fameless but Widespread Web Vulnerability Class
Description
Two key components account for finding vulnerabilities of a certain class: awareness of the vulnerability and ease of finding the vulnerability. Cross-Site Script Inclusion (XSSI) vulnerabilities are not mentioned in the de facto standard for public attention – the OWASP Top 10 [1]. Additionally there is no publicly available tool to facilitate finding XSSI. The impact reaches from leaking personal information stored, circumvention of token-based protection to complete compromise of accounts. XSSI vulnerabilities are fairly wide spread and the lack of detection increases the risk of each XSSI. In this paper I am going to demonstrate how to find XSSI, exploit XSSI and also how to protect against XSSI exploitation.
Notes
Files
Cross-Site Script Inclusion - A Fameless but Widespread Web Vulnerability Class.pdf
Files
(363.2 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:49e4852aad240e7f9a97a0251632f1cb
|
363.2 kB | Preview Download |