XSS vulnerability detection method and device
A vulnerability detection and to-be-detected technology, applied in the field of XSS vulnerability detection, can solve problems such as poor accuracy of detection results, and achieve the effect of solving poor accuracy, avoiding missed judgments and misjudgments, and improving accuracy
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0024] According to an embodiment of the present invention, a method for detecting XSS vulnerabilities is provided, such as image 3 As shown, the method includes:
[0025] S102: Obtain the URL of the webpage to be detected and the executable script code of the web server where the webpage to be detected is located;
[0026] S104: updating the script code into the URL of the webpage to be detected;
[0027] S106: Use the updated URL to access the webpage to be detected;
[0028] S108: Determine whether the web server executes the script code;
[0029] S110: If the web server executes the script code, it is determined that the webpage to be detected has a cross-site scripting attack (XSS) vulnerability.
[0030] It should be clear that one of the problems to be solved by the embodiments of the present invention is to provide a method for effectively detecting XSS vulnerabilities.
[0031] XSS vulnerability is a computer security vulnerability that often appears in web pages...
Embodiment 2
[0074] According to an embodiment of the present invention, there is also provided a detection device for implementing the XSS vulnerability of the above detection method, such as Figure 9 As shown, the device includes:
[0075] 1) Acquisition unit 902, used to obtain the Uniform Resource Identifier URL of the webpage to be detected and the executable script code of the Web server where the webpage to be detected is located;
[0076] 2) update unit 904, for updating the script code in the URL of the webpage to be detected;
[0077] 3) an access unit 906, configured to use the updated URL to access the webpage to be detected;
[0078] 4) judging unit 908, used to judge whether the web server executes the script code;
[0079] 5) The output unit 910 is configured to determine that the webpage to be detected has a cross-site scripting attack (XSS) vulnerability when the web server executes the script code.
[0080] It should be clear that one of the problems to be solved by t...
Embodiment 3
[0123] According to an embodiment of the present invention, a storage medium for storing the process entities of the detection method described in Embodiment 1 is also provided, such as Figure 10 As shown, the storage medium is configured to store program code for performing the following steps:
[0124] S1002: Obtain the URL of the webpage to be detected and the executable script code of the web server where the webpage to be detected is located;
[0125] S1004: updating the script code into the URL of the webpage to be detected;
[0126] S1006: Use the updated URL to access the webpage to be detected;
[0127] S1008: Determine whether the web server executes the script code;
[0128] S1010: If the web server executes the script code, it is determined that the webpage to be detected has a cross-site scripting attack (XSS) vulnerability.
[0129] Optionally, in this embodiment, the above-mentioned storage medium can be located in such as figure 2 On the background server...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com