CAPEC-63
Cross-Site Scripting (XSS)
An adversary embeds malicious scripts in content that will be served to web browsers. The goal of the attack is for the target software, the client-side browser, to execute the script with the users' privilege level. An attack of this type exploits a programs' vulnerabilities that are brought on by allowing remote hosts to execute code and scripts. Web browsers, for example, have some simple security controls in place, but if a remote attacker is allowed to execute scripts (through injecting them in to user-generated content like bulletin boards) then these controls may be bypassed. Further, these attacks are very difficult for an end user to detect.
Soyutlama
Standard
Tipik ciddiyet
Very High
Saldırı ihtimali
High
Saldırıyı anla
Bu saldırı kalıbı nedir?
Uygulama akışı
Saldırı adım adım nasıl ilerler?
Explore
Survey the application for user-controllable inputs
Kullanılan teknikler
- Use a spidering tool to follow and record all links and analyze the web pages to find entry points. Make special note of any links that include parameters in the URL.
- Use a proxy tool to record all links visited during a manual traversal of the web application.
- Use a browser to manually explore the website and analyze how it is constructed. Many browsers' plugins are available to facilitate the analysis or automate the discovery.
Experiment
Probe identified potential entry points for XSS vulnerability
Kullanılan teknikler
- Use a list of XSS probe strings to inject script in parameters of known URLs. If possible, the probe strings contain a unique identifier.
- Use a proxy tool to record results of manual input of XSS probes in known URLs.
- Use a list of XSS probe strings to inject script into UI entry fields. If possible, the probe strings contain a unique identifier.
- Use a list of XSS probe strings to inject script into resources accessed by the application. If possible, the probe strings contain a unique identifier.
Exploit
Steal session IDs, credentials, page content, etc.
Kullanılan teknikler
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and sends document information to the attacker.
- Develop malicious JavaScript that injected through vectors identified during the Experiment Phase and takes commands from an attacker's server and then causes the browser to execute appropriately.
Forceful browsing
Kullanılan teknikler
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and performs actions on the same web site
- Develop malicious JavaScript that injected through vectors identified during the Experiment Phase and takes commands from an attacker's server and then causes the browser to execute request to other web sites (especially the web applications that have CSRF vulnerabilities).
Content spoofing
Kullanılan teknikler
- Develop malicious JavaScript that is injected through vectors identified during the Experiment Phase and loaded by the victim's browser and exposes attacker-modified invalid information to the user on the current web page.
Gereksinimler
Saldırının gerçekleşmesi için ne gerekir?
Ön koşullar
- Target client software must be a client that allows scripting communication from remote hosts, such as a JavaScript-enabled Web Browser.
Gerekli beceri
- Low: To achieve a redirection and use of less trusted source, an attacker can simply place a script in bulletin board, blog, wiki, or other user-generated content site that are echoed back to other client machines.
- High: Exploiting a client side vulnerability to inject malicious scripts into the browser's executable process.
Gerekli kaynak
- Ability to deploy a custom hostile service for access by targeted clients. Ability to communicate synchronously or asynchronously with client machine.
Etki
Başarılı saldırı neye yol açar?
Etkilenen alanlar: Confidentiality, Integrity, Availability
Etkilenen alanlar: Integrity
Etkilenen alanlar: Confidentiality
Savunma
Nasıl önlenir ve etkisi azaltılır?
Gerçek dünya