Start networking and exchanging professional insights

Register now or log in to join your professional community.

Follow

What are Cross-Site Scripting (XSS) attacks ?

user-image
Question added by Adel Ezat Fawzy Ellozy , Webdeveloper. , Saudi Arabian Maritiem Sports Federation
Date Posted: 2017/02/20
khalil malki
by khalil malki , Senior Developer , Delta airlines

Hi,

 

I think OWASP has the best answers to this:

https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)

 

Preventing this takes steps on front and back. Plus, it depends on the programing language you are using and the framework.

 

 

Ehab  Shaker
by Ehab Shaker , Dot Net Developer , Info Strategic

XSS is a security breach that takes advantage of dynamically generated Web pages.

it enables attackers to inject client-side scripts into web pages viewed by other users

Thank you for the question, I learnt from previous answers

Adel Ezat Fawzy Ellozy
by Adel Ezat Fawzy Ellozy , Webdeveloper. , Saudi Arabian Maritiem Sports Federation

The idea of xss is that a hacker can inject their own custom JavaScript into a webpage. It's used to trick users into running their custom JavaScript code. And they also used to steal cookies. And if they steal cookies they can steal the cookies data as well as potentially session data, which has been linked with a cookie.

Mohammed Akbar Shariff
by Mohammed Akbar Shariff , Product Security Engineer , Phonepe India Pvt Ltd

XSS(cross site scripting) in simple words is running user written script in text input box of any website and watching the same script reflecting on the website, which is a huge vulnerability, without any admin privilege a Attacker will be able to manipulate or change website's UI with which one can be fooled for malicious content or attacker might steal cookies with session information etc, brief explanation on this can be obtained at OWASP or Acunetix website.

Ahmed Elbasuny
by Ahmed Elbasuny , CRM Consultant and web developer , Nas Manpower

really its a big gap in web site design ...why its famous Gap

 because meny of  web sites like Apple ,Uponto its hacked by this gap

this depend on Client Side programming Languages 

see that to understand more

https://www.acunetix.com/websitesecurity/cross-site-scripting/

Adam Ahmed
by Adam Ahmed , IT & Web Developer , Freelance

Basm allah alrahman alrahim

 

look at wikipedia XSS

 

 

More Questions Like This

Do you need help in adding the right keywords to your CV? Let our CV writing experts help you.