×

Detection of DOM-based cross-site scripting vulnerabilities

  • US 9,223,977 B2
  • Filed: 04/16/2012
  • Issued: 12/29/2015
  • Est. Priority Date: 10/28/2011
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of testing a Web-based application for security vulnerabilities, the method comprising:

  • communicating at least one client request comprising a payload having a unique identifier to the Web-based application;

    responsive to communicating the at least one client request comprising the payload having the unique identifier to the Web-based application, receiving from the Web-based application response hypertext markup language (HTML) and an associated Document Object Model (DOM) object, the DOM object including the unique identifier communicated to the web-based application in the payload;

    via a processor, identifying in the DOM object the unique identifier communicated to the web-based application in the payload; and

    responsive to identifying in the received DOM object the unique identifier communicated to the web-based application in the payload, identifying as un-trusted a section of the received DOM object comprising content corresponding to the payload, which is identified in the received DOM object via the unique identifier.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×