Cross-Site Scripting - CompTIA Security+ SY0-701 - 2.3

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/4

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:44 AM on 3/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

5 Terms

1
New cards

Cross Site Scripting

• XSS

• Cascading Style Sheets (CSS)

are something else entirely

• Originally called cross-site

because of browser security flaws

• Information from one site

could be shared with another

• One of the most common

web application development errors

• Takes advantage of the trust a user has for a site

• Complex and varied

• Malware that uses JavaScript

• Do you allow scripts? Me too.

<p>• XSS</p><p>• Cascading Style Sheets (CSS)</p><p>are something else entirely</p><p>• Originally called cross-site</p><p>because of browser security flaws</p><p>• Information from one site</p><p>could be shared with another</p><p>• One of the most common</p><p>web application development errors</p><p>• Takes advantage of the trust a user has for a site</p><p>• Complex and varied</p><p>• Malware that uses JavaScript</p><p>• Do you allow scripts? Me too.</p>
2
New cards

Non-persistent (reflected) XSS attack

Web-site allows scripts to run in user input

- search box is a common source

Attacker emails a link that takes advantage of this vulnerability

- Runs a script that send credentials/session ID's/cookies to the attacker

Script embedded in URL executed in the victims browser

Attacker uses credentials/sessions ID's/cookies to steal victims infomration without their knowledge

<p>Web-site allows scripts to run in user input</p><p>- search box is a common source</p><p>Attacker emails a link that takes advantage of this vulnerability</p><p>- Runs a script that send credentials/session ID's/cookies to the attacker</p><p>Script embedded in URL executed in the victims browser</p><p>Attacker uses credentials/sessions ID's/cookies to steal victims infomration without their knowledge</p>
3
New cards

Persistent (stored) XSS attack

• Attacker posts a message to a social network

- Includes the malicious payload

• It's now "persistent" - Everyone gets the payload

• No specific target - All viewers to the page

• For social networking, this can spread quickly

- Everyone who views the message can have it

posted to their page

- Where someone else can view it and propagate it further...

4
New cards

Hacking a Subaru

June 2017, Aaron Guzman

- Security researcher

When authenticating with Subaru, users get a token

- This token never expires (bad!)

A valid token allowed any service request

- Even adding your email address to someone

else's account

- Now you have full access to someone else's car

Web front-end included an XSS vulnerability

- A user clicks a malicious link, and you have

their token

5
New cards

Protecting against XSS

- Be careful when clicking untrusted links

- Consider disabling JavaScript, or control with an extension

- Keep your browser and applications updated

- Keep your web server applications updated

Explore top notes

note
Criminal Psychology
Updated 682d ago
0.0(0)
note
COM 100 Test: Chapters 1-8
Updated 542d ago
0.0(0)
note
6.5: The Great Depression
Updated 1253d ago
0.0(0)
note
CGO casus 2
Updated 437d ago
0.0(0)
note
Beck Anxiety Inventory
Updated 1163d ago
0.0(0)
note
Ch. 3; Energy
Updated 1029d ago
0.0(0)
note
Criminal Psychology
Updated 682d ago
0.0(0)
note
COM 100 Test: Chapters 1-8
Updated 542d ago
0.0(0)
note
6.5: The Great Depression
Updated 1253d ago
0.0(0)
note
CGO casus 2
Updated 437d ago
0.0(0)
note
Beck Anxiety Inventory
Updated 1163d ago
0.0(0)
note
Ch. 3; Energy
Updated 1029d ago
0.0(0)

Explore top flashcards

flashcards
Week 9
31
Updated 539d ago
0.0(0)
flashcards
Module 11
65
Updated 732d ago
0.0(0)
flashcards
troika “my family”
21
Updated 1219d ago
0.0(0)
flashcards
AP Spanish Literature - Autores
39
Updated 330d ago
0.0(0)
flashcards
Learn to Lead Chapter 1 Review
28
Updated 769d ago
0.0(0)
flashcards
Week 9
31
Updated 539d ago
0.0(0)
flashcards
Module 11
65
Updated 732d ago
0.0(0)
flashcards
troika “my family”
21
Updated 1219d ago
0.0(0)
flashcards
AP Spanish Literature - Autores
39
Updated 330d ago
0.0(0)
flashcards
Learn to Lead Chapter 1 Review
28
Updated 769d ago
0.0(0)