Cross site scripting
Attacker can inject malicious scripts to a vulnerable website, that executes on victim user’s browser
mitigations:
- Encode output when you need to display user input; Variables should be interpreted as text, not code
- Sanitize user input when allowing users to author HTML (e.g. WYSIWYG editor)
Intro
Once script executes on victim user's browser, it can do pretty much anything Javascript can do (without mitigation controls).
- access cookies - such as session tokens or other sensitive info, then send these to attacker site
- manipulate DOM - deface website, load external content
- Redirect victim to attacker site
- account impersonation - perform actions under user’s guise on the vulnerable site
- etc
Typically, XSS happens when user input is used to generate response, without validation or encoding. Common inputs involved are:
- URL params accepted by server