Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
XSS
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Mike Klemarewski
April 05, 2016
Programming
74
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
XSS
A quick overview of cross site scripting
Mike Klemarewski
April 05, 2016
More Decks by Mike Klemarewski
See All by Mike Klemarewski
Redux Containers Demystified
mikeklemarewski
1
71
HTTPS
mikeklemarewski
1
66
Injection
mikeklemarewski
1
72
Handy Shell Commands
mikeklemarewski
2
76
Other Decks in Programming
See All in Programming
Webエンジニアなのにブラウザの仕組みがわからないので、Pythonで自作してみた
tatsuki12
4
850
自動化したのに回らないテスト運用の壁ーAI時代の品質責任と生産性
mfunaki
1
150
わからない話を追いかけたら、プログラミング言語を作る側にいた
ydah
3
530
AI時代に設計が 最大の生産性レバーになる 意図駆動開発とデータを消さない設計|Don't Delete Your Data or Your Intent — Design as the Deepest Lever in the AI Era
tomohisa
1
1.1k
S3 を使うアプリケーションをローカル完結で動かすことに全力を注いでみた / Running S3 Apps Offline
contour_gara
0
560
進化を続けるGo toolsの現在地 / The Current State of Ever-Evolving Go Tools
hond0413
0
250
Pythonの実行はどこまで賢くなったのか? CPythonとPyPyから見る最適化のしくみ
curekoshimizu
0
190
AIを紡ぐPMのお話
swdtkuy
0
120
テーブルをDELETEした
yuzneri
0
150
Go 1.27 における memory allocation の高速化
andpad
0
280
今さら聞けない .NET CLI
htkym
0
200
Cloudflare is Agents
chimame
0
170
Featured
See All Featured
Getting science done with accelerated Python computing platforms
jacobtomlinson
2
440
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
810
ラッコキーワード サービス紹介資料
rakko
1
4.4M
Building Adaptive Systems
keathley
44
3.2k
Become a Pro
speakerdeck
PRO
31
6.2k
The Hidden Cost of Media on the Web [PixelPalooza 2025]
tammyeverts
2
470
Hiding What from Whom? A Critical Review of the History of Programming languages for Music
tomoyanonymous
3
1.1k
How to Ace a Technical Interview
jacobian
281
24k
Docker and Python
trallard
47
4.1k
svc-hook: hooking system calls on ARM64 by binary rewriting
retrage
2
510
My Coaching Mixtape
mlcsv
0
250
Navigating Team Friction
lara
192
16k
Transcript
XSS (Cross Site Scripting)
What is it? • Text based attack • Exploits the
browser's interpreter, allowing the attacker to run code on the target site
What can be done using XSS? • hijack user sessions
• insert content • redirect users • hijack the user’s browser using malware
Who can do these attacks? • Anyone that can send
data to the system • Anyone that can craft a url and put it in front of other people
Types of XSS
Stored • User input is stored on the server and
rendered to any user that visits the page • Eg. User reviews, comments, profiles
Reflected • User input is returned by the web application
and rendered without being sanitized • Eg. Search results
DOM Based XSS • The response doesn't contain the exploit
payload • Some client side code reads the malicious data from the URL or DOM and executes it
Demo! Great resource from Google
Example attacks • Samy MySpace Worm • Spread through 1
million users in 20 hours • StrongWebmail CEO email hacked • XSS Worm Examples
Prevention • Properly escape untrusted data • Input validation can
help, but isn't a full solution • Use sanitization libraries
FIN