Главная
Study mode:
on
1
Introduction
2
Overview
3
Slides
4
Same Origin Policy
5
XSS vulnerability
6
XSS Types
7
What is DOMBase
8
How to stop XS attacks
9
Clients XSS
10
Automated expert generator
11
Alexa top 10000 domains
12
Disabling the XSS auditor
13
Testing the XSS auditor
14
Crosssite scripting attack
15
Inline scripts
16
Attributes
17
External Content
18
Preventing the XSS Auditor
19
Performance
20
Avoiding invocation
21
String matching issues
22
Partial injections
23
Trailing content
24
Demo
25
Solution
26
Example
27
False Negatives
28
False Positives
29
Performance Results
30
Conclusion
Description:
Explore a comprehensive conference talk from AppSecEU 2015 in Amsterdam, where Martin Johns, Sebastian Lekies, and Ben Stock delve into client-side protection against DOM-based XSS attacks. Learn about the Same Origin Policy, XSS vulnerability types, and the specifics of DOM-based XSS. Discover effective methods to stop cross-site scripting attacks, including automated expert generators and the XSS auditor. Examine real-world testing scenarios using Alexa top 10000 domains and understand the challenges of disabling and testing XSS auditors. Gain insights into preventing XSS auditor bypasses, performance considerations, and string matching issues. Watch a demo showcasing solutions, examples, and potential false negatives and positives. Conclude with performance results and key takeaways for implementing robust client-side protection against DOM-based XSS vulnerabilities.

Client-Side Protection Against DOM-Based XSS Done Right

OWASP Foundation
Add to list