Downloads provided by UsageCounts
Two key components account for finding vulnerabilities of a certain class: awareness of the vulnerability and ease of finding the vulnerability. Cross-Site Script Inclusion (XSSI) vulnerabilities are not mentioned in the de facto standard for public attention – the OWASP Top 10 [1]. Additionally there is no publicly available tool to facilitate finding XSSI. The impact reaches from leaking personal information stored, circumvention of token-based protection to complete compromise of accounts. XSSI vulnerabilities are fairly wide spread and the lack of detection increases the risk of each XSSI. In this paper I am going to demonstrate how to find XSSI, exploit XSSI and also how to protect against XSSI exploitation.
This paper was written in 2016 as part of a research project at scip AG, Switzerland. It was initially published online at https://www.scip.ch/en/?labs.20160414 and is available in English and German. Providing our clients with innovative research for the information technology of the future is an essential part of our company culture.
Exploit, HTML, Risk, XSSi, JSON, Twitter, Block, Javascript, Burp, Internet Explorer, GitHub, RSA, Social Engineering, Report, Browser, CSRF, Request, False Positive, Microsoft, OWASP, HTTP, Research, Tracking, Penetration Test, Conference, Detect, Google, Policy, API, Tool, Firefox, Leak, Oracle
Exploit, HTML, Risk, XSSi, JSON, Twitter, Block, Javascript, Burp, Internet Explorer, GitHub, RSA, Social Engineering, Report, Browser, CSRF, Request, False Positive, Microsoft, OWASP, HTTP, Research, Tracking, Penetration Test, Conference, Detect, Google, Policy, API, Tool, Firefox, Leak, Oracle
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
| views | 14 | |
| downloads | 11 |

Views provided by UsageCounts
Downloads provided by UsageCounts