NOTE
1.9 XSS
XSS causes and defenses such as contextual output encoding.
This is a historical learning note and may contain outdated or incomplete understanding.
1. What Is an XSS Attack
A kind of web attack.
For example, user A enters <script>alert(1)</script>. If it is output into HTML without being correctly escaped or encoded, user B will keep seeing an alert when opening the page.
2. Why XSS Attacks Happen
The primary condition for XSS is that the response Content-Type is text/html, and then illegal user input is treated as code and executed.
3. How to Defend Against XSS Attacks
- Option 1: correctly escape or encode user input when outputting it.
- Option 2: for a non-HTML endpoint, exclude
text/htmlfrom theContent-Typeand useX-Content-Type-Options: nosniff.
4. Example
4.1. Non-HTML Endpoint
- Exclude
text/htmlfrom the Content-Type so that the browser does not parse the response as HTML. However, because some browsers have content-sniffing behavior and may still parse this kind of endpoint as an HTML page, add theX-Content-Type-Options: nosniffheader to the HTTP response.
Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub