Cross-Site Scripting (XSS) - Types and Prevention
About 2 min read
Cross-site scripting (XSS) is an attack technique that injects malicious scripts into web pages. JavaScript planted by an attacker runs in the victim's browser, leading to cookie theft, session hijacking, redirects to phishing pages, and more. In the 2024 OWASP Top 10 it ranks high as a type of injection attack, and it is one of the most common vulnerabilities in web applications.
What Decides the Risk Is Not the Value but Where It Is Placed
Whether a received value causes a problem is not decided by how the value looks. The same sequence of characters is handled differently depending on whether it lands where text is placed, where an attribute inside a marker is placed, or where instructions are read; a character that carries no meaning in one place acts as a separator in another. For that reason, a scheme that normalizes uniformly at the point of acceptance will always be off in one direction or the other when there are several destinations. Only the processing immediately before the value is written out knows the destination, so the place to normalize can be at the exit and not at the entrance. Next, the fact that the screen receiving a value and the screen showing it are different creates a stretch across which premises do not travel. The showing side does not know the assumptions of the receiving side, and if it was built at another time for another purpose, the arrangements settled on the receiving side never reach it. Therefore having done work on the receiving side does not mean the showing side is safe. The number of things to verify grows as the number of receiving points multiplied by the number of showing points. And the reading takes place not under the control of the side that stored the value but in the hands of the person viewing it. The makeup of that environment is invisible from the storing side, and no record of what was read there remains with the storing side either. What remains is only the record that the value was accepted, so the routes to noticing are limited to reviewing the accepted content afterwards or tracing back from results observed on the outside.
The Flow of an XSS Attack
Types of XSS
Reflected XSS is a type in which a script contained in a URL parameter is reflected directly into the page. Stored XSS is a type in which a script saved in the database is displayed to other users; bulletin boards and the comment sections of social media are frequent targets, and it causes more serious damage. DOM-based XSS is a type that originates from client-side JavaScript processing and is difficult to detect because it does not pass through the server.
Concrete Damage Scenarios
A common misconception is that "XSS is a minor attack that only changes the appearance." In reality, serious attacks are possible, such as using stored XSS to embed a malicious script in the product review section of an e-commerce site and steal the session cookies of every user who views the review. With the stolen cookies, the attacker can purchase products using the victim's account or change their registered information. Techniques that combine it with phishing to display a fake login form on a legitimate site have also been observed.
Countermeasures as a User
The basics are to keep your browser up to date and not click on suspicious links. By using a unique random password for each service, you can prevent damage from spreading to other services even if a session is hijacked through an XSS attack. Restricting JavaScript execution with a browser extension is also an effective countermeasure.
Was this article helpful?