The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Objectives Greece is one of the leading tobacco-producing countries in European Union, and every year over 19 000 Greeks die from tobacco-at...
-
Objectives Drug interactions, poor adherence to medication and high-risk sexual behaviour may occur in individuals with HIV using recreation...
-
Introduction Multimorbidity (MM) refers to the coexistence of two or more chronic conditions within one person, where no one condition is co...
-
Objective To describe the prevalence and severity of diabetic retinopathy (DR) and sight-threatening DR (STDR) among Chinese adults with dia...
-
Related Articles Three job stress models and their relationship with musculoskeletal pain in blue- and white-collar workers. J Psycho...
-
Abstract Background Mature T-cell and natural killer (NK)-cell lymphomas compose a heterogeneous group of non-Hodgkin lymphomas, and ext...
-
<span class="paragraphSection"><div class="boxTitle">Abstract</div>Masked hypertension (MHT), defined ...
-
Background Hepatitis B virus (HBV) transmission is known to occur through direct contact with infected blood. There has been some suspicion ...
-
In Rwanda, the prevalence of viral hepatitis (HCV) is poorly understood. The current study investigated the prevalence and risk factors of H...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου