J4 ›› 2011, Vol. 33 ›› Issue (10): 45-50.
• 论文 • Previous Articles Next Articles
FENG Kai,LIN Bogang
Received:
Revised:
Online:
Published:
Abstract:
With the popularity of the Web2.0 applications, crosssite scripting vulnerability which can cause a serious threat to the safety of users exists in a wide range of websites, due to the lack of proper verification mechanisms. Currently, the mixture of the serverside and clientside codes makes accurate and effective detection of crosssite scripting vulnerability more difficult. In our study, based on a static data flow analysis combined with a string constraint solving technique, we design a whitebox testing framework for detecting crosssite scripting vulnerability. We implement our framework in a prototype tool called XSSExplore, and the experimental results show that the system can better generate a more effective attack vector and detect crosssite scripting attacks compared with similar products.
Key words: Web security;XSS;static analysis;fuzzing;whitebox testing
FENG Kai,LIN Bogang. Design and Implementation of a XSS Vulnerability Whitebox Testing Framework[J]. J4, 2011, 33(10): 45-50.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2011/V33/I10/45