Detection method and system for interactive XSS (Cross-Site Scripting) vulnerability
A detection method and detection system technology, which are applied in the field of detection methods and systems for interactive XSS vulnerabilities, can solve problems such as failure to detect XSS vulnerabilities, and achieve the effect of successful detection.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0023] figure 1 A flowchart of a method for detecting an interactive XSS vulnerability provided by the first embodiment of the present invention is shown, and the details are as follows:
[0024] Step S11, send the detection request with the feature value constructed to the Web server, and receive the response page returned by the Web server;
[0025] In this step, the XSS detection tool receives and saves the http request sent by the client to the web server, and constructs a feature value according to the http request; specifically, based on the received and saved user http request, each http request is modified one by one The parameter value is modified into the characteristic value. The characteristic value is a string, and its purpose is to attempt XSS injection attack. For example, an eigenvalue could be: , if there is no XSS encoding protection on the page, the div will be inserted into the DOM structure as a DOM node. In addition, for different page output points,...
Embodiment 2
[0054] image 3 A structural diagram showing an interactive XSS vulnerability detection system provided by the second embodiment of the present invention For convenience of description, only parts related to the embodiment of the present invention are shown. The detection system for the interactive XSS vulnerability includes: a detection request sending unit 31, a DOM listener parsing unit 32, an intelligent event simulator parsing unit 33, and a judging unit 34, wherein:
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com