35
. xss Cross Site Scripting

Cross site scripting

Embed Size (px)

DESCRIPTION

XSS is one type of vulnerability which is existing in most of the web application .Due to this vulnerabilityit may have chance to to deface website nad cookie steatling,session hijacking etc.

Citation preview

Page 1: Cross site scripting

.

xss

Cross Site Scripting

Page 2: Cross site scripting

Cross site scripting Vulnerabilities Cross site request forgery Attacks

Web Application Security Issues

Page 3: Cross site scripting

Cross site request forgery

Page 4: Cross site scripting

Cross site scripting :outline

Page 5: Cross site scripting

Client line scripting

Page 6: Cross site scripting

Cross Site Scripting Vulnerabilities

Page 7: Cross site scripting

XSS Concept

Page 8: Cross site scripting

Attack Scenarios

Page 9: Cross site scripting

XSS risks vs Attack scenarios

Page 10: Cross site scripting

Attack Scenario 1

Page 11: Cross site scripting

Stolen Account Credentials

Page 12: Cross site scripting

Cookie machanism and vulnerability

Page 13: Cross site scripting

XSS point for cookies

Page 14: Cross site scripting

Privacy Risks

Page 15: Cross site scripting

Attack Scenario 2:Same Site Exploit

Page 16: Cross site scripting

Misinformation modification and self Propagation

Page 17: Cross site scripting

Same site Phishing

Page 18: Cross site scripting

Attack Scenario 3:Brouser Exploits

Page 19: Cross site scripting

Browser Exploit :other page modification

Page 20: Cross site scripting

Denial of Service

Page 21: Cross site scripting

Browser exploit: silent install

Page 22: Cross site scripting

Defeated Security Zones Model

Page 23: Cross site scripting

Defeated accountability

Page 24: Cross site scripting

History of malicious scripts

Page 25: Cross site scripting

Other Malicious Scripts

Page 26: Cross site scripting

VB Scripts that change registry keys

Page 27: Cross site scripting

Myspace Worm

Page 28: Cross site scripting

Types of XSS VULNERABILITIES

Page 29: Cross site scripting

XSS Vulnerality ;Reflection

Page 30: Cross site scripting

Results

Page 31: Cross site scripting

XSS Vulnerability :Stored

Page 32: Cross site scripting

XSS vulnerability :Indirect

Page 33: Cross site scripting

Java script injection methods

Page 34: Cross site scripting

Java script URL`S

Page 35: Cross site scripting

Variation on indirect injection