It's More Than Stealing Cookies - Exploitability of XSS
K. Nirmal, B. Janet, R. Kumar · 2018
Web Application vulnerabilities are into existence since the beginning of the internet and the world-wide web. In recent years, it has been given more importance considering the rapid expansion of online presence of critical businesses. There have been tremendous contributions by open source projects like Open Web Application Security Project in the area of web application security. Through open source projects, the attack vectors and mitigation specifications are shared to the developer community. There has been tremendous improvement in mitigation specifications and framework level protection for common web application vulnerabilities like Cross Site Scripting (XSS). Automated web application scanners have evolved over a period of time to aid in the detection of vulnerabilities at an early phase. Though there have been mitigation specifications in place and tools to detect vulnerabilities, attackers have always found new methods and payloads to circumvent the protection mechanisms. Analysis of a widely-used web based email service resulted in uncovering a specific methodology using which XSS can be exploited leveraging the working principle of CORS (Cross Origin Resource Sharing) in web browsers. A CVE (Common Vulnerabilities and Exposures) number was assigned for this instance and the same was logged in NVD (National Vulnerability Database). During the analysis, in depth insights on why and where automated security scanners fail was demonstrated.