Cross-Site Scripting (XSS)

intermediateWeb

TL;DR

Cross-Site Scripting (XSS) is when an app reflects attacker-controlled input back into a page without properly encoding it, so the browser runs it as code. The fix is to treat all output as data: encode it for the context it lands in, and set a Content Security Policy.

Only test apps you own or are authorised to test.

What it is

A web page mixes the app’s own markup with data. If user input ends up in the page without being encoded, the browser can’t tell your data from the app’s code, and it will run script that shouldn’t be there. That’s XSS.

How it works

There are three flavours you’ll meet:

How to test for it

At heart, testing for XSS is checking whether input can break out of its context and be treated as markup:

How to fix it

Reference: OWASP: Cross-Site Scripting and the XSS prevention cheat sheet.

← Back to Web