Главная
Study mode:
on
1
Intro
2
The Problem
3
Detect Access asleep
4
What did I find
5
Defacement
6
Cookie stealing
7
Data steal
8
Attack intensity
9
Fixing XSS
10
Find Your Vaults
11
Leveraging the Browser
12
Conditionally pushing down JavaScript
13
Automating virtual patching
14
Browser filters
15
Attack methodology
16
Clientside analysis
Description:
Explore a comprehensive analysis of cross-site scripting (XSS) vulnerabilities and defense strategies in this Black Hat USA 2013 conference talk. Delve into the findings of a large-scale data mining study that uncovered successful XSS exploits on over 1,000 vulnerable pages across hundreds of websites worldwide. Examine various attack scenarios, including defacement, cookie stealing, and data theft, while gaining insights into attack intensity and patterns. Learn about cutting-edge protection methods capable of intercepting more than 95% of real-world malicious samples. Discover the newly introduced detectXSSlib, a lightweight nginx module for real-time XSS attack detection. Gain valuable knowledge on fixing XSS vulnerabilities, leveraging browser capabilities, implementing conditional JavaScript, automating virtual patching, and utilizing browser filters. Understand attack methodologies and clientside analysis techniques to enhance your web security posture.

The Web Is Vulnerable - XSS Defense on the BattleFront

Black Hat
Add to list