A server administrator gathers tools for an upcoming security audit of systems. Which solution would the administrator find useful for discovering cross-site scripting (XSS) vulnerabilities?
Added by Jose M.
Step 1
Popular tools include OWASP ZAP, Burp Suite, and Acunetix. Show more…
Show all steps
Your feedback will help us improve your experience
Aarya B and 54 other AP CS educators are ready to help you.
Ask a new question
Labs
Want to see this concept in action?
Explore this concept interactively to see how it behaves as you change inputs.
Key Concepts
Recommended Videos
Start your Kali and OWASP BWA VMs. Confirm the IP address of the OWASP BWA VM. All future steps are to be performed from your Kali VM. Open http://<OWASP BWA IP>/ in Firefox and select OWASP WebGoat. If you are asked to authenticate, use the account webgoat/webgoat. Browse to Cross-Site Scripting -> Reflected XSS Attacks. Identify which fields are vulnerable to XSS. Craft a script input that sets the price of each item in your Shopping Cart to $0 and the Quantity of each item to 999.
Aarya B.
To defeat XSS attacks, a developer decides to implement filtering on the browser side. Basically, the developer plans to add JavaScript code on each page, so before data is sent to the server, it filters out any JavaScript code contained inside the data. Let's assume that the filtering logic can be made perfect. Can this approach prevent XSS attacks?
Akash M.
In this lab, students will create a free account on the Cloud Security Alliance website and download a Top Threats study. Students will be asked to analyze a vulnerability, choose an appropriate control, and perform a little more research to back that selection up with facts. This lab will give students exposure to the Cloud Security Alliance top threat program. Students should go to the CSA page / Knowledge Center / Research Library (Links to an external site.) and create a free account. Sign in and open the following document: Top Threats to Cloud Computing: Deep Dive. Scroll down to the Cloudbleed vulnerability and read the one-page details. Students are to select one of these two categories - Preventative Controls or Detective Controls. Under this category, choose which control you believe to be the most effective and explain why. What to submit in your Lab Report: Vulnerability: Cloudbleed Select one - Preventative or Detective: Most Important Control and Why: Research: Do some research and try to find an example of where your chosen control could have prevented CloudBleed from being impactful.
Recommended Textbooks
Computer Science and Information Technology
Introduction to Programming Using Python
Computer Science - An Overview
Transcript
18,000,000+
Students on Numerade
Trusted by students at 8,000+ universities
Watch the video solution with this free unlock.
EMAIL
PASSWORD