Home > Ask the Security Experts > Information Security Threats Questions & Answers > Has cross-site scripting evolved?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Has cross-site scripting evolved?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 August 2007
What's new with cross-site scripting? Isn't this just an old attack from a decade ago? Why all the buzz about it now?

>
EXPERT RESPONSE
Today's cross-site scripting (XSS) tactics are a far cry from the attacks of the late 1990s, a time when hackers were popping up dialog boxes and swiping e-commerce cookies from browsers. While those early threats are still with us, attacks have become far more serious. With the emergence of a new development method known as Asynchronous JavaScript and XML (AJAX), the scripts that a Web site can push to a browser have more capabilities than ever before.

To see what can happen, consider this attack scenario: You find yourself surfing to a site belonging to an attacker, or even an innocent Web site that hosts content from millions of other users, such as a social networking site, an auction site or a Web-based email site. (An innocent Web site is just as likely to propagate an XSS flaw if it doesn't properly scrub user input to filter out browser scripts.) Once there, evil script programs are dutifully passed down to your browser. The browser then runs the scripts, interpreting them as being sent by the site.

"And then what?" you ask. Well, mayhem ensues. A script, running in the browser, can do anything you can do on that site: bid on an auction, buy stuff or expand your buddy list to include unsavory people. But it gets worse. The script could scrape your browser history to see if you've visited any embarrassing Web sites, and in turn forward the information back to the attacker. The script could also use the browser to start scanning other Web servers, perhaps even those inside of your corporation's firewall.

It's astounding what is being done with browser scripts these days. And, all of this is possible just because you surfed to the attacker's site, or viewed an attacker's content on a third-party location. For more details on these threats, check out the startling presentation by Billy Hoffman at this year's Shmoocon show, an East Coast hacking convention.

So in a nutshell, an attacker can use the browser to wield bot-like control of a victim's machine. Sure, there are restrictions on what scripts can do in a browser. They can't directly access any file in the file system or run arbitrary programs on the machine, for example, but clever researchers are finding ways to either dodge those restrictions or live within them to achieve powerful controls.

What can you do to defend yourself? On highly sensitive machines, you may want to disable browser scripts altogether. Also, make sure you keep your antivirus tool up to date. And, watch this trend carefully. There's big stuff coming in this realm, to be sure.

More information:

  • Learn which techniques can prevent cross-site scripting.
  • Michael Cobb reviews database vulnerabilities. XSS is only the beginning.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Information Security Threats
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    Defining mobile device security concerns
    What security measures can be taken to stop crimeware kits?
    What software development best practices can prevent input validation attacks?
    What is the most secure way for application developers to manage cookies?
    Is there a market for standalone antivirus products?
    Can 'herd intelligence' effectively stop malware?

    Mobile Code (Active X, JavaScript)
    Researcher: Beware of massive IFrame attack
    IT discussion: Is malware the cause of a DNS server error?
    iPhone not ready for the enterprise
    CA works to patch BrightStor flaws
    Symantec fixes flaws in Norton, pcAnywhere
    Anatomy of a zero-day: Security researchers face hurdles
    Super Bowl stadium Web site hacked, delivered malware
    Security Blog Log: Taking Google Code Search for a spin
    Brief: Malicious Web site poses as Google
    Mozilla still looking into Firefox flaw claims

    Web Application Security (Also see Web Access Control)
    Tracing malware's steps with RE:Trace
    SQL injection attack infects hundreds of thousands of websites
    PCI Council issues clarification on Web application security
    IBM's Watchfire halts network research, focuses on Web apps
    Web scanning and reporting best practices
    How to prevent software piracy
    NAC, disk encryption gaining attention, survey shows
    Shrewd attackers bypass old security defenses with Web attacks
    PCI DSS Section 6: A plan for tackling application security
    What Web security initiatives can be taken on a college campus?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cache cramming  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts