×

Persistent cross-site scripting vulnerability detection

  • US 9,948,665 B2
  • Filed: 06/04/2015
  • Issued: 04/17/2018
  • Est. Priority Date: 11/25/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting a persistent cross-site scripting vulnerability comprising:

  • inserting, via a processor, a client-side script as input into a web application;

    requesting, via the processor, data from the web application;

    in response to requesting the data, detecting that resource is sent from a client device to an external computing device in response to execution of the client-side script on the client device, wherein the external computing device is a different device than the client device;

    receiving at the external computing device, the inserted client-side script in response to requesting data from the web application;

    receiving from the external computing device, the inserted client-side script, in response to receiving the client-side script at the external computing device;

    detecting, via the processor, that the client-side script is subsequently returned unaltered via the data request by comparing the inserted client-side script with the received client side script, and that execution of the client-side script occurs.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×