The high-profile attacks of malicious HTML and JavaScript code have seen a dramatic increase in both awareness and exploitation in recent years. Unfortunately, exiting security mechanisms provide no enough protection. We propose a new protection mechanism named PMHJ based on the support of both web applications and web browsers against malicious HTML and JavaScript code in vulnerable web applications. PMHJ prevents the injection attack of HTML elements with a random attribute value and the node-split attack by an attribute with the hash value of the HTML element. PMHJ ensures the content security in web pages by verifying HTML elements, confining the insecure HTML usages which can be exploited by attackers, and disabling the JavaScript APIs which may incur injection vulnerabilities. PMHJ provides a flexible way to rein the high-risk JavaScript APIs with powerful ability according to the principle of least authority. The PMHJ policy is easy to be deployed into real-world web applications. The test results show that PMHJ has little influence on the run time and code size of web pages.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/1VMr3fw
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Abstract Objective Accurate and precise measurement of vestibular schwannoma (VS) size is key to clinical management decisions. Linear mea...
-
A. M. Homes reads Shirley Jackson’s short story “The Lottery,” and discusses it with The New Yorker’s fiction editor, Deborah Treisman. fr...
-
Marshall McLuhan predicted the global village, one world interconnected by an electronic nervous system, making it part of our popular cultu...
-
Featuring original free math problem solving worksheets for teachers and parents to copy for their kids. Use these free math worksheets for ...
-
brings you inside access to tickets, artist news, and exclusive stories on concerts, tours, sports teams, family events, arts, theater, and ...
-
Canons of Criticism. Contents: Introduction * Outline of the Canons * External Critical Rules * Internal Critical Rules * How to Use the Can...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nRQGPr via IFTTT
-
Ginger explains the definition of abstract & concrete nouns, gives you examples of use, a list of abstract nouns, exercises & more. ...
-
Love it, or we’ll pick it up! Ron Arvine, President of Arvine Pipe & Supply Co., Inc. has built his reputation in the oil field by stand...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου