Back to Search
Start Over
RTF Editor XSS Fuzz Framework
- Source :
- Innovative Mobile and Internet Services in Ubiquitous Computing ISBN: 9783319615417, IMIS
- Publication Year :
- 2017
- Publisher :
- Springer International Publishing, 2017.
-
Abstract
- Cross Site Scripting (XSS) is one of the most important vulnerabilities in web applications, has been in the top three position of OWASP TOP10 [1] security risks for a long time. In many web application components, RTF (Rich Text Format) Editor has a wide range of XSS attacks because of its own characteristics. With the development of XSS detection technology, Fuzz technique has become a popular approach to discover XSS in web applications except Rich Text Editor. Thus, this paper proposes a RTF Editor XSS fuzz framework, which works on a lexical based fuzz framework. This framework includes an attack vector template and a mutation engine. In this framework, we use a concept named “boundary” to build the template and use a method named “breaking boundaries” to generate mutated data. Experimental results of our fuzz framework are quite encouraging. We have run it over 12 real-world RTF Editor (including Webmail, Blog, Markdown editor, etc.) and found vulnerabilities in 8 of them. We have responsibly reported our findings to the respective developers of editors.
- Subjects :
- 021110 strategic, defence & security studies
Computer science
business.industry
Cross-site scripting
Rich Text Format
0211 other engineering and technologies
02 engineering and technology
computer.file_format
computer.software_genre
World Wide Web
020204 information systems
0202 electrical engineering, electronic engineering, information engineering
Web application
business
computer
Markdown
Range (computer programming)
Subjects
Details
- ISBN :
- 978-3-319-61541-7
- ISBNs :
- 9783319615417
- Database :
- OpenAIRE
- Journal :
- Innovative Mobile and Internet Services in Ubiquitous Computing ISBN: 9783319615417, IMIS
- Accession number :
- edsair.doi...........fe694a75539b8cedabb1265dd7861cd5