Analysis of Advance Manual Detection and Robust Prevention of Cross-Site Scripting in Web-Based Services
Smit Swant, Gaurav Choudhary, Shishir Kumar Shandilya, Lokesh M. Giripunje, Vikas Kumar Sihag · Apple Academic Press eBooks · 2024
With the increase in internet users, the number of intruders and attackers is also increasing; this leads to security issues associated with web applications. These web applications are prone to many vulnerabilities due to a lack of secure coding practices by web developers, which in turn risks the privacy and confidential data of end-users using such web applications. Cross-site scripting (XSS) vulnerabilities are one of the most common bugs that affect most modern web applications. The nature of cross-site 154 scripting has been always evolving and its risk impact on web applications varies from medium severity to critical severity. The traditional defense mechanism could not cope with various bypass techniques to trigger XSS even if there is some kind of protection mechanism to prevent it, for reference the Cuneiform-alphabet based XSS payload bypasses Cloudflare firewall protection mechanism against cross-site scripting attacks. In this chapter, We have analyzed the major concerns for defense mechanisms against cross-site scripting attacks and came up with some robust security solutions which can be integrated with the traditional cross-site scripting defense methodologies to prevent all kinds of cross-site scripting attacks. For finding cross-site scripting bugs, manual detection techniques are robust as it locates vulnerabilities in the website’s dark corners while automatic vulnerability scanners have high false-positive and false-negative rates. The overall security of any web application can be enhanced with proposed non-responsive or non-dynamic search boxes which are implemented to prevent cross-site scripting attacks. The combined use of website security plugins with firewalls increases the robustness of web applications. Technique to discover Reflected cross-site scripting (XSS) attacks in URL paths and use of xsshunter, an online platform to find blind cross-site scripting attacks also boosts web applications against all types of cross-site scripting (XSS) attacks.