NOTE

1.9 XSS

XSS causes and defenses such as contextual output encoding.

SecurityCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. What Is an XSS Attack

A kind of web attack. For example, user A enters <script>alert(1)</script>. If it is output into HTML without being correctly escaped or encoded, user B will keep seeing an alert when opening the page.

2. Why XSS Attacks Happen

The primary condition for XSS is that the response Content-Type is text/html, and then illegal user input is treated as code and executed.

3. How to Defend Against XSS Attacks

  1. Option 1: correctly escape or encode user input when outputting it.
  2. Option 2: for a non-HTML endpoint, exclude text/html from the Content-Type and use X-Content-Type-Options: nosniff.

4. Example

4.1. Non-HTML Endpoint

  1. Exclude text/html from the Content-Type so that the browser does not parse the response as HTML. However, because some browsers have content-sniffing behavior and may still parse this kind of endpoint as an HTML page, add the X-Content-Type-Options: nosniff header to the HTTP response.

5. References

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub