DSpace Repository

Automated Discovery of JavaScript Code Injection Attacks in PHP Web Applications

Show simple item record

dc.contributor.author Gupta, Shashank
dc.date.accessioned 2024-11-05T11:54:29Z
dc.date.available 2024-11-05T11:54:29Z
dc.date.issued 2016
dc.identifier.uri https://www.sciencedirect.com/science/article/pii/S1877050916000168
dc.identifier.uri http://dspace.bits-pilani.ac.in:8080/jspui/handle/123456789/16300
dc.description.abstract This paper discussed some of the performance issues in the existing defensive solutions of Java Script injection attacks (e.g. Cross-Site Scripting (XSS) attacks). Moreover, a high level of comparison for such existing solutions has been done based on some useful metrics. Based on the identified performance issues, this paper proposed an automated detection system, which scans the numerous possible locations of web sites for JavaScript injection vulnerabilities. Our detection system, firstly, scans the web site for discovering the injection locations. Secondly, it injects the malicious XSS attack vectors in such injection points. Lastly, it takes an input as the list of different XSS attacks exploited in the second step and scan for these attacks in the vulnerable web application. Detection capability of our automated system is evaluated on a real world PHP web application i.e. BlogIt and results obtained are very promising. en_US
dc.language.iso en en_US
dc.publisher Elsevier en_US
dc.subject Computer Science en_US
dc.subject Cross-Site Scripting (XSS) attacks en_US
dc.subject JavaScript Injection Vulnerabilities en_US
dc.subject XSS Cheat Sheet en_US
dc.title Automated Discovery of JavaScript Code Injection Attacks in PHP Web Applications en_US
dc.type Article en_US


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account