The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2o3fxRd via IFTTT
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2pf2BXI via IFTTT
-
Nephrolithiasis accelerates the renal failure in the patients with ADPKD. In order to evaluate the role of percutaneous nephrolithotomy in m...
-
A mass-change-based method based on output-only data for the rescaling of mode shapes in operational modal analysis (OMA) is introduced. The...
-
by Maggie Zgambo, Balwani Chingatichifwe Mbakaya, Fatch Welcome Kalembo Background Malaria is the main cause of morbidity and mortality amo...
-
Voice alterations in patients with Morquio A syndrome. J Appl Genet. 2017 Dec 23;: Authors: Szklanny K, Gubrynowicz R, Tylki-Szymańsk...
-
Communicate solutions that will reduce the impact of humans on the land, water, air, and/or other living things in the local environment.* ...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2ns8lB3 via IFTTT
-
Cancer Cytopathology Mark above section as read Case Reports in Pathology Mark above section as read Clinical Anatomy Mark above section as ...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου