针对危害性最为严重的存储型XSS漏洞的特点及其触发方式,设计并实现了一款自动生成存储型XSS攻击向量的工具.使用该工具对中国2个大型视频分享网站的日志发布系统进行测试,发现6类导致存储型XSS漏洞的攻击向量.实验结果验证了该方法及测试工具的有效性,并说明中国视频网站仍存在着较大安全隐患.
The stored-XSS (cross-site scripting) is generally more serious than the other modalities of XSS. We study the characteristics and trigger mechanism of stored-XSS, propose an generation method of attack vectors for stored-XSS, and accomplish a tool which can generate the attack vectors automatically. After we used this tool in testing the blog systems of two popular video-sharing sites in China, we found 6 types of attcak vectors which can trigger stored-XSS. The results of the testing experiments show the effectiveness of our method and also show the potential security risk in the video-sharing sites.
[1] 新浪微博XSS攻击事件分析 [EB/OL](2011-08-30) [2011-09-22]. http://netsecurity.51cto.com/art/201108/287982.htm
[2] Galn E, Alcaide A, Orfila A, et al. A multi-agent scanner to detect stored-XSS vulnerabilities [C]//IEEE Internet Technology and Secured Transactions (ICITST). London, 2010: 1-6.
[3] Kieyzun A, Guo P J, Jayaraman K, et al. Ernst automatic creation of SQL injection and cross-site scripting attacks [C]//IEEE ICSE, Vancouver. Canada, 2009:199-209.
[4] Chen J Q, Zhang Y Q. Design and realization of web cross-site scripting vulnerability detection tool[J]. Computer Engineering, 2010, 36(6):152-157(in Chinese). 陈建青,张玉清. Web跨站脚本漏洞检测工具的设计与实现[J]. 计算机工程,2010,36(6):152-157.
[5] XSS (cross site scripting) cheat sheet [DB/OL]. [2011-09-02]. http://ha.ckers.org/xss.html.
[6] Tang Z S, Zhu H J, Cao Z F, et al. L-WMxD: lexical based Webmail XSS discoverer [C]//IEEE Computer Communications Workshops (INFOCOM WKSHPS). Shanghai, 2011:976-981.
[7] Qiu Y J. Study on techniques of cross-site scripting attack and defense [D]. Beijing: Beijing Jiaotong University, 2010(in Chinese). 邱勇杰. 跨站脚本攻击与防御技术研究 [D]. 北京:北京交通大学,2010.
[8] Gebre MT, Lhee K, Hong M. A robust defense against content-sniffing XSS attacks [C]//IEEE Multimedia Technology and its Applications (IDC). Barcelona, 2010:315-320.
[9] HTML4.0事件属性 [EB/OL]. [2011-09-20]. http://www.w3school.com.cn/html/html_eventattributes.asp.
[10] Stuttard D, Pinto M. The web application Hacker's handbook: discovering and exploiting security flaws[M]. America: Wiley Publishing Inc, 2008:406-410.
[11] Sutton M, Greene A, Amini P. Fuzzing brute force vulnerability discovery[M]. America: Pearson Education Inc, 2007:140-144.