The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
4995879043233 Swing Low, Staple Singers, Stapsingers 9780340891070 0340891076 Hod Cat - Sceptre Catalogue Jul 9781560630821 1560630825 Babil...
-
IZE is a professional association dedicated to expanding the educational impact of zoos and aquariums worldwide, to enhance the understandin...
-
Copyright © 1999-2007 by , Kai Froeb. Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free ...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nhPCs5 via IFTTT
-
Greens Blue Flame supplies propane tank installation services and propane delivery in the Houston, TX area. We also offer bulk commercial de...
-
A topic sentence is a sentence, sometimes at the beginning of a paragraph, that states or suggests the main idea (or topic) of a passage. ...
-
A Vietnam War Timeline [Note: This timeline is an abbreviated version of the more detailed timeline posted on the Public Broadcasting System...
-
Disclaimer: All personages on drawings over 18 age. -high- has a zero-tolerance policy against illegal pornography. All content and links ar...
-
1,001 FREE cover letter examples and samples for consultants, career changers, and job hunters. The FIRST and BEST cover letters on the Inte...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου