首页> 外文学位 >Exploring security vulnerabilities that are introduced in Cascading Style Sheets.
【24h】

Exploring security vulnerabilities that are introduced in Cascading Style Sheets.

机译:探索级联样式表中引入的安全漏洞。

获取原文
获取原文并翻译 | 示例

摘要

Cascading Style Sheets (CSS) are applied directly to Hypertext Markup Language (HTML) in order to apply Web page style. The style changes to Web pages are simplified and applied quickly by using external style sheets or by using embedded or inline style declarations. Style declarations work directly with HTML tags and malicious scripts can be applied to HTML. This study was initiated to determine if CSS was vulnerable to malicious scripting. Employing qualitative research, two case studies were applied using Microsoft security bulletins to identify security vulnerabilities pertaining to CSS cross-domain disclosure and memory corruption. The study also identified methods for improving Web site security. Vulnerabilities to malicious scripting were confirmed in CSS as was the fact that CSS hacks did not improve Web page security. It is recommended that users and developers need to be aware of security intrusions that occur using Web page links or through access to any content or object located on a Web page. Users, developers, and network administrators are encouraged to implement and apply security precautions. Future research could include examination of source code pertaining to Web-based application security.
机译:级联样式表(CSS)直接应用于超文本标记语言(HTML),以应用网页样式。通过使用外部样式表或嵌入式或嵌入式样式声明,可以简化并快速应用Web样式的更改。样式声明可直接与HTML标记一起使用,恶意脚本可应用于HTML。开始这项研究是为了确定CSS是否容易受到恶意脚本的攻击。通过定性研究,使用Microsoft安全公告应用了两个案例研究,以识别与CSS跨域披露和内存损坏有关的安全漏洞。该研究还确定了提高网站安全性的方法。 CSS证实了恶意脚本的漏洞,因为CSS骇客并没有提高Web页面的安全性。建议用户和开发人员需要注意使用网页链接或通过访问网页上任何内容或对象而发生的安全入侵。鼓励用户,开发人员和网络管理员实施和应用安全预防措施。未来的研究可能包括检查与基于Web的应用程序安全性有关的源代码。

著录项

  • 作者

    Di Tomasso, Don.;

  • 作者单位

    Northcentral University.;

  • 授予单位 Northcentral University.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2009
  • 页码 131 p.
  • 总页数 131
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 自动化技术、计算机技术;
  • 关键词

  • 入库时间 2022-08-17 11:38:25

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号