The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Abstract Recent updating of the World Health Organization (WHO) classification of central nervous system (CNS) tumors in 2016 demonstrates...
-
In our previous work, the dichloromethane-methanol (1:1 v/v) extract, fractions and isolated compounds from Polyscias fulva stem bark showed...
-
Background Agricultural work can expose workers to increased risk of heat strain and volume depletion due to repeated exposures to high ambi...
-
Cincinnati.com No fooling; go get your head (and neck) examined for free Cincinnati.com Thursday, get your head examined. UC Health ...
-
Anaphora is a rhetorical term for the repetition of a word or phrase at the beginning of successive clauses or verses. from #AlexandrosSfa...
-
Nursing students' perceptions of a video-based serious game's educational value: A pilot study. Nurse Educ Today. 2017 Dec 28;...
-
Abstract We introduce a novel diagnostic Visual Voiding Device (VVD), which has the ability to visually document urinary voiding events an...
-
Method combines radiomics with three - compartment breast image analysis of dual - energy mammography (Source: The Doctors Lounge - Oncology...
-
Cone beam computerized tomography (CBCT) has been widely used in dental implanting. However, the local hospitals usually don’t have access t...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου