Главная
Study mode:
on
1
Introduction
2
Overview
3
State of Automated XSS Detection
4
Key Idea
5
History
6
Different Syntax
7
Techniques
8
Payload Slam
9
Signature Bass
10
completeness
11
string transformation
12
unique slugs
13
sandwich method
14
detection logic
15
trace
16
real life example
17
browser considerations
18
key takeaways
19
practice
20
input output
21
getpost
22
dom
23
dynamic
24
dynamic payload
25
dynamic exploit
26
bash shell
27
should deploy
Description:
Explore new methods in automated XSS detection without relying on static payloads in this 41-minute conference talk from AppSecUSA 2015. Delve into dynamic techniques for identifying XSS vulnerabilities, including accurate Stored XSS detection and generation of custom XSS exploits. Compare current automated XSS detection methods with their limitations to innovative dynamic analysis approaches. Learn how to create dynamic custom XSS exploits based on the presented detection methods. Gain insights into various techniques such as payload slam, signature bass, string transformation, unique slugs, and the sandwich method. Examine real-life examples, browser considerations, and key takeaways for practical implementation. Cover input/output handling, GET/POST requests, DOM manipulation, and dynamic payload generation. Conclude with guidance on deploying these advanced XSS detection strategies in your security practices.

New Methods in Automated XSS Detection - Dynamic Testing Without Static Payloads

OWASP Foundation
Add to list