期刊文献+

基于跨站脚本的网络漏洞攻击与防范 被引量:13

Attack and Prevention on Defects of Web Page Based on Cross Site Scripting
在线阅读 下载PDF
导出
摘要 目前很多的Web应用程序为了提高用户体验都包含大量动态内容,从而给Web应用程序带来了安全隐患。而跨站脚本攻击(XSS)是目前安全漏洞中排在前列并引起广泛注意的安全隐患之一。本文主要分析跨站脚本攻击漏洞存在形式和攻击产成流程,并总结出XSS攻击的防范方法。
出处 《计算机系统应用》 2008年第1期38-40,44,共4页 Computer Systems & Applications
  • 相关文献

参考文献4

二级参考文献4

  • 1University College London, 26 Gordon Square, London, WC1.The bentham project [J/OL]. URL: http:∥www. ucl.ac.uk/Bentham-Project/index.htm.
  • 2The internet encyclopedia of philosophy [J/OL]. URL: http:∥www. utm.edu/research/iep/m/millj s.htm#Utilitarianism.
  • 3Denning, Dorothy E. Concerning hackers who break into computer systems[J/OL].Paper presented at the 13th National Computer Security Conference, Washington, 1990, (10): 1-4. URL:http:∥www. cpsr. org/cpsr/privacy/crime/denning.hackers.html.
  • 4Sinbad[EB/OL]. 2002. http:∥sinbad.zhoubin.com/read.html.

共引文献16

同被引文献60

  • 1张勇,李力,薛倩.Web环境下SQL注入攻击的检测与防御[J].现代电子技术,2004,27(15):103-105. 被引量:55
  • 2古开元,周安民.跨站脚本攻击原理与防范[J].网络安全技术与应用,2005(12):19-21. 被引量:15
  • 3欧阳无敌@.渗透方法论之脚本篇[J].黑客防线,2007(7):33-35. 被引量:2
  • 4Martin M, Lam MS. Automatic generation of XSS and SQL injection attacks with goal-directed model checking. Proc. of the 17th Conference on Security Symposium Jul. 2008.
  • 5Kirda E, Kruegel C, Vigna G, Jovanovic P. Noxes: a client-side solution for mitigating cross-site scripting attacks. Proc. of the 2006 ACM Symposium on Applied computing Apr. 2006.
  • 6Jim T, Swamy P, Hicks PM. Defeating script injection attacks with browser-enforced embedded policies. Proc. of the 16th International Conference on World Wide Web May. 2007.
  • 7Grossman J. Cross-site scripting worms and viruses the Impending Threat and the Best Defense. APRIL 2006.
  • 8Karlof C, Shankar U, Tygar JD, Wagner D. Dynamic pharming attacks and the locked same-origin policies for web browsers. Proc. of the 14th ACM Conference on Computer and Communications Security (CCS 2007), November 2007.
  • 9国家互联网应急中心.CNCERT/CC2008年上半年网络安全工作报告[EB/OL].[2009-05-04].http://www.cert.org.cn/UserFiles/File/CISR2008fh.pdf1.pdf.
  • 10HTTPOnly-OWASP. HTTPOnly[EB/OL]. (2009-08-15). [2009-08-15]. http://www. owasp. org/index. php/HTTPOnly#Browsers_ Supportin g_ HTTPOnly.

引证文献13

二级引证文献41

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部