CAPEC-63
Cross-Site Scripting (XSS)
An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.
Abstraction
Standard
Typical severity
Very High
Likelihood of attack
High
Understand the attack
What is this attack pattern?
Execution flow
How does the attack proceed, step by step?
Explore
Survey the application for user-controllable inputs
Techniques used
- Use a spidering tool to follow and record all links and analyze the web pages to find entry points. Make special note of any links that include parameters in the URL.
- Use a proxy tool to record all links visited during a manual traversal of the web application.
- Use a browser to manually explore the website and analyze how it is constructed. Many browsers' plugins are available to facilitate the analysis or automate the discovery.
Experiment
Probe identified potential entry points for XSS vulnerability
Techniques used
- Use a list of XSS probe strings to inject script in parameters of known URLs. If possible, the probe strings contain a unique identifier.
- Use a proxy tool to record results of manual input of XSS probes in known URLs.
- Use a list of XSS probe strings to inject script into UI entry fields. If possible, the probe strings contain a unique identifier.
- Use a list of XSS probe strings to inject script into resources accessed by the application. If possible, the probe strings contain a unique identifier.
Exploit
Steal session IDs, credentials, page content, etc.
Techniques used
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and sends document information to the attacker.
- Develop malicious JavaScript that injected through vectors identified during the Experiment Phase and takes commands from an attacker's server and then causes the browser to execute appropriately.
Forceful browsing
Techniques used
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and performs actions on the same web site
- Develop malicious JavaScript that injected through vectors identified during the Experiment Phase and takes commands from an attacker's server and then causes the browser to execute request to other web sites (especially the web applications that have CSRF vulnerabilities).
Content spoofing
Techniques used
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and exposes attacker-modified invalid information to the user on the current web page.
Requirements
What does the attack require?
Prerequisites
- Target client software must be a client that allows scripting communication from remote hosts, such as a JavaScript-enabled Web Browser.
Skills required
- Low: To achieve a redirection and use of less trusted source, an attacker can simply place a script in bulletin board, blog, wiki, or other user-generated content site that are echoed back to other client machines.
- High: Exploiting a client side vulnerability to inject malicious scripts into the browser's executable process.
Resources required
- Ability to deploy a custom hostile service for access by targeted clients. Ability to communicate synchronously or asynchronously with client machine.
Impact
What does a successful attack lead to?
Affected scopes: Confidentiality, Integrity, Availability
Affected scopes: Integrity
Affected scopes: Confidentiality
Defence
How is it prevented and mitigated?
Real world