Methods for determining cross-site scripting and related vulnerabilities in applications
a cross-site scripting and vulnerability technology, applied in the direction of instruments, computing, electric digital data processing, etc., can solve the problem that testing will fail to detect the vulnerability in the web si
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Benefits of technology
Problems solved by technology
Method used
Image
Examples
example 1
GET Method Example 1
[0160]
Step 1:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.php?HTMLtext=HTML2ndtext&HTMLtext=HTMLtext&HTMLattDQ=HTMLattDQ&HTMLattSQ=HTMLattSQ&scriptattr=scriptattr&scripttag=scripttagSteps 2 and 3:HTMLtext=HTML2ndtextStep 4:2f6b4e8Steps 5 and 6:HTMLtext=2f6b4e8Step 7:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.php?HTMLattDQ=2f6b4e8&HTMLattSQ=HTMLattSQ&HTMLtext=HTML2ndtext&scriptattr=scriptattr&scripttag=scripttag
example 2
GET Method Example 2
[0161]
Step 1:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.php?HTMLtext=HTML2ndtext&HTMLtext=HTMLtext&HTMLattDQ=HTMLattDQ&HTMLattSQ=HTMLattSQ&scriptattr=scriptattr&scripttag=scripttagStep 2 and 3:HTMLattSQ=HTMLattSQStep 4:78752efSteps 5 and 6:HTMLattSQ=78752efStep 7:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.php?HTMLattSQ=78752ef&HTMLattDQ=HTMLattDQ&HTMLtext=HTML2ndtext&scriptattr=scriptattr&scripttag=scripttag
POST Method Example (Parameters are Parsed from HTML Form Tags)
[0162]
Step 1:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.phpSteps 2 and 3:HTMLattSQ=HTMLattSQStep 4:78752efSteps 5 and 6:HTMLattSQ=78752efStep 7:h-t-t-p-: / / 192.168.56.103 / testScripts / reflect.php{u′post-data′: {u′HTMLattDQ′: u″, u′HTMLtext′: u″, u′scripttag′: u″,u′scriptattr′: u″, u′HTMLattSQ′: u′78752ef′}}
[0163]For the following original URL, examples are provided thereafter of URL-tested (URL-slugged versions) generated and submitted.
Original URL: h-t-t-p-: / / 192.168.56.103 / testScripts / refl...
case 1 example
[0205]
md5sum = 5a105e8b9d40e1329780d62ea2265d8aStep 1:5a105e8b9d40e1329780d62ea2265d8aStep 2:5a105e8b9d40e1329780d62ea2265d8a 5a105e8b9d40e1329780d62ea2265d8a5a105e8b9d40e1329780d62ea2265d8a >5a105e8b9d40e1329780d62ea2265d8a5a105e8b9d40e1329780d62ea2265d8a / 5a105e8b9d40e1329780d62ea2265d8a5a105e8b9d40e1329780d62ea2265d8a (5a105e8b9d40e1329780d62ea2265d8a5a105e8b9d40e1329780d62ea2265d8a ′5a105e8b9d40e1329780d62ea2265d8a5a105e8b9d40e1329780d62ea2265d8a )5a105e8b9d40e1329780d62ea2265d8aStep 3:5a105e8b9d40e1329780d62ea2265d8aalert(‘xss’) 5a105e8b9d40e1329780d62ea2265d8aStep 4:(Part 1)(Part 2)Step 5:5a105e8b9d40e1329780d62ea2265d8a pt>alert(‘xss’) 5a105e8b9d40e1329780d62ea2265d8aStep 6:alert(‘xss’)
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 