The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Todas as cores do Matte Batom Stick da Vult são matte? Sim, toda a coleção tem este efeito. from #AlexandrosSfakianakis via Alexandros G.S...
-
How to Write a Master's Thesis. Students learning how to write a Master's Thesis will first learn that a central thesis question mus...
-
BY JONATHAN MARCANTONI — It was in the 90s when I began writing, first on a cheap computer program my dad bought me that mixed cut out anima...
-
The argumentative essay, although bearing many similarities to the persuasive (argument) essay, has several very distinct differences. fro...
-
Look Up Your Lawmaker Look up your lawmakers and track their votes by email in two easy steps with MegaVote. from #AlexandrosSfakianakis v...
-
Nursing Care Study This assignment is a case study of a patient who was admitted to a respiratory ward with acute exacerbation of asthma. Th...
-
Looking for argumentative and persuasive essay topics? 50 great ideas at your disposal. Check out this list of hot topics! from #Alexandro...
-
Guitar chords and guitar tablature made easy. Chordie is a search engine for finding guitar chords and guitar tabs. from #AlexandrosSfakia...
-
We provide excellent essay writing service 24/7. Enjoy proficient essay writing and custom writing services provided by professional academi...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου