Visible to the public An Analytical Study on Cross-Site Scripting

TitleAn Analytical Study on Cross-Site Scripting
Publication TypeConference Paper
Year of Publication2020
AuthorsSingh, M., Singh, P., Kumar, P.
Conference Name2020 International Conference on Computer Science, Engineering and Applications (ICCSEA)
Keywordsbrowser side script, Cross Site Scripting, cross-site scripting, fake malicious website, Human Behavior, injection, input validation, malicious scripts, Non-persistent XSS attack, Persistent XSS attack, phishing attack, pubcrawl, resilience, Resiliency, Scalability, security of data, symantic states, Web application, Web sites, XSS attack, XSS vulnerabilities
AbstractCross-Site Scripting, also called as XSS, is a type of injection where malicious scripts are injected into trusted websites. When malicious code, usually in the form of browser side script, is injected using a web application to a different end user, an XSS attack is said to have taken place. Flaws which allows success to this attack is remarkably widespread and occurs anywhere a web application handles the user input without validating or encoding it. A study carried out by Symantic states that more than 50% of the websites are vulnerable to the XSS attack. Security engineers of Microsoft coined the term "Cross-Site Scripting" in January of the year 2000. But even if was coined in the year 2000, XSS vulnerabilities have been reported and exploited since the beginning of 1990's, whose prey have been all the (then) tech-giants such as Twitter, Myspace, Orkut, Facebook and YouTube. Hence the name "Cross-Site" Scripting. This attack could be combined with other attacks such as phishing attack to make it more lethal but it usually isn't necessary, since it is already extremely difficult to deal with from a user perspective because in many cases it looks very legitimate as it's leveraging attacks against our banks, our shopping websites and not some fake malicious website.
DOI10.1109/ICCSEA49143.2020.9132894
Citation Keysingh_analytical_2020