Cross-site Scripting - CompTIA Security+ SY0-701 - 2.3 — Transcript
Full transcript
- 0:02in this video we'll talk about
- 0:03cross-site scripting and you may see
- 0:05this also abbreviated as
- 0:07xss it seems like we would use the
- 0:09abbreviation CSS for cross-site
- 0:12scripting but that abbreviation has
- 0:14already been taken by cascading
- 0:16stylesheets so instead we use xss to be
- 0:19able to differentiate between both of
- 0:21those Technologies this attack type was
- 0:23originally called cross-site scripting
- 0:25because of vulnerabilities that we found
- 0:28inside of our browsers these vulner IL
- 0:30is created a situation inside of your
- 0:32browser where information from one site
- 0:34could be shared with another site crossy
- 0:37scripting is one of the most common
- 0:39vulnerabilities for web-based
- 0:40applications this takes advantage of the
- 0:43trust that the browser has for different
- 0:45websites although there are challenges
- 0:47in creating a cross-site scripting
- 0:48exploit once you have that exploit there
- 0:51are many different ways to take
- 0:52advantage of it many of these cross-side
- 0:55scripting vulnerabilities are based
- 0:56around an attack using JavaScript
- 0:59JavaScript scpt is a very popular
- 1:01scripting language within our browsers
- 1:03and practically everyone has JavaScript
- 1:05enabled in their
- 1:07browser from a high level let's see how
- 1:09a cross-side scripting attack might be
- 1:11exploited let's start with the victim
- 1:13that would be our system a trusted
- 1:15website that we might commonly associate
- 1:18with and of course there is the attacker
- 1:20one way that you could exploit a
- 1:22cross-site scripting vulnerability is
- 1:24for the attacker to send a link to the
- 1:25victim that has a malicious script
- 1:28inside of it this could be sent over
- 1:30email it might be a text message or any
- 1:32other method that would get that
- 1:34malicious link into the hands of the
- 1:36victim the victim will click the link
- 1:38inside of that message which takes them
- 1:40to a legitimate site and it's one that's
- 1:42trusted by the victim but because the
- 1:45attacker has provided this link there's
- 1:47additional information included with
- 1:49this connection usually it's a malicious
- 1:51script that's also running along with
- 1:54the connection to the trusted website
- 1:56this malicious script is not usually
- 1:57seen by the victim but behind the scenes
- 1:59means there's data that's being sent
- 2:01directly to the attacker this might
- 2:03include cookie information session
- 2:05details other specifics on that
- 2:07particular website and anything else
- 2:09that may be considered private or secure
- 2:12information one common type of a
- 2:14cross-site scripting attack is a
- 2:16non-persistent attack this might also be
- 2:19called a reflected attack this is one
- 2:21where a third-party website might be
- 2:24configured in a way that would allow
- 2:26people to run scripts inside of these
- 2:28user input blocks a website like this
- 2:31one providing a search engine should not
- 2:33allow someone to run their own
- 2:35JavaScript within that input box that's
- 2:38exactly what has been found here by an
- 2:40attacker the attacker is going to email
- 2:42that link that takes advantage of that
- 2:44vulnerability and behind the scenes that
- 2:46script is going to send those private
- 2:48details to the attacker so the attacker
- 2:50is the one sending the malicious code to
- 2:52the user but the user is the one
- 2:54executing that malicious code against a
- 2:57thirdparty website the thirdparty
- 2:59website May send session ID information
- 3:01to the attacker which means the attacker
- 3:03will now have the same access to that
- 3:05thirdparty website as the victims's
- 3:08machine here's an example of a website
- 3:10that has a cross-site scripting
- 3:11vulnerability this is one that has a
- 3:13shopping cart in it you can see there
- 3:15are a number of items within the
- 3:16shopping cart and on this particular
- 3:18site it's the credit card number field
- 3:20that does not do any type of checking
- 3:22for scripts which means we could embed a
- 3:25script within that credit card number
- 3:27field to be able to perform this cross
- 3:29site scripting attack so here I've
- 3:31created a very small amount of
- 3:33JavaScript it's a very simple script
- 3:35that simply puts an alert message on the
- 3:37screen and that alert message shows your
- 3:40session information and then the session
- 3:42ID within the cookie for this site so
- 3:45when we're putting in credit card
- 3:46information we would also include that
- 3:48entire script along with the credit card
- 3:50details and you can see we've pasted it
- 3:52in on that credit card field when we
- 3:55click the purchase button a message
- 3:56appears on the screen with the
- 3:58information about our session and it
- 4:00includes the session ID now obviously
- 4:03the attacker is not going to have a
- 4:05session ID message pop up on your screen
- 4:07instead that session ID will be sent
- 4:09directly to the attacker behind the
- 4:11scenes and the victim has no idea that
- 4:13that session information is now in the
- 4:15hands of the
- 4:17attacker instead of the attacker trying
- 4:19to find some specific way to directly
- 4:22send a link to a user what if the
- 4:25attacker simply posted the link on
- 4:27Facebook this is the idea behind a
- 4:29persistent or stored cross-site
- 4:31scripting attack the attacker will post
- 4:33a message on a social media site and it
- 4:36will include with that message the
- 4:38malicious payload which is probably
- 4:40malicious JavaScript this is why it's
- 4:42now called persistent because the
- 4:44attacker has now stored that information
- 4:47on that thirdparty social networking
- 4:49site everyone who visits that page with
- 4:51the malicious software will effectively
- 4:54have that code run inside of their
- 4:55browser from the attacker perspective
- 4:58this means that they're effectively
- 4:59attacking everyone who visits that
- 5:01social networking page so all of the
- 5:04viewers of that information will have
- 5:06that JavaScript run inside of their
- 5:08local browser and because this is a
- 5:10social networking site the attacker
- 5:12might include other code that would
- 5:14allow people to share their malicious
- 5:16code so anyone who views this message
- 5:19can have it posted to their own feed on
- 5:21that social media site and the next
- 5:23person that views it on their feed goes
- 5:25through the exact same process and again
- 5:28and again as this m message is now
- 5:30spread to all of these different users
- 5:32using a persistent or stored cross-site
- 5:35scripting attack an interesting crossy
- 5:37scripting attack was found in June 2017
- 5:40by Aon Guzman he's a security researcher
- 5:43who is looking at the Subaru front end
- 5:46on their website that allows them to
- 5:48manage different capabilities within
- 5:50their vehicle when you log into the
- 5:52Subaru website you get a token and this
- 5:55token never expires which from a best
- 5:58practices perspective I is probably not
- 6:00the best idea normally there would be
- 6:02some expiration for instance the token
- 6:05might expire in a day which would
- 6:06require you to log in again after 24
- 6:09hours Not only was there no expiration
- 6:12associated with this token the token
- 6:14allowed you to perform any service
- 6:16request on your vehicle not only did
- 6:18this create a security concern for your
- 6:20vehicle but you could add your email
- 6:22address to someone else's account and
- 6:25the same token would allow you access
- 6:27into managing their veh vehicle as well
- 6:30the cross-site scripting part of this is
- 6:32a vulnerability that was also on the
- 6:34Subaru website which means an attacker
- 6:37could send a link with malicious code
- 6:39inside of it and receive the token for
- 6:42that particular Subaru website from the
- 6:44victim and now since we know that this
- 6:46token has such power as soon as the
- 6:49attacker has that copy of a user's token
- 6:52they're able to use it forever because
- 6:54the token doesn't expire and if the
- 6:55attacker adds their email address to
- 6:58another Subaru account that same token
- 7:00will also grant them access to that
- 7:03account this is effectively a single
- 7:05token that allows an attacker full
- 7:07access to anyone's vehicle that may be
- 7:10registered on the Subaru website
- 7:12fortunately this particular
- 7:13vulnerability was found by a security
- 7:15researcher who informed Subaru of the
- 7:17issue and they were able to resolve and
- 7:20remove these
- 7:21vulnerabilities there's a few things we
- 7:23can do to protect ourself against a
- 7:25cross-site scripting attack one of these
- 7:28is to not click a link that you may not
- 7:30already trust you should not click links
- 7:32inside of your email your messages or
- 7:35anything else that's coming from a third
- 7:37party instead you should open a browser
- 7:39separately and only type in domain names
- 7:42that you can trust you may want to
- 7:44consider either disabling JavaScript or
- 7:47limiting the capabilities of JavaScript
- 7:49sometimes you can do that with a browser
- 7:51plug-in but this offers limited
- 7:53protection and ultimately it may limit
- 7:55what website you're able to visit
- 7:57perhaps most importantly you should
- 7:59always make sure that your browser and
- 8:01your applications are always updated to
- 8:03the latest version as manufacturers
- 8:05locate and identify these cross-site
- 8:07scripting vulnerabilities they will push
- 8:09out patches to prevent your browser from
- 8:11being susceptible to these problems and
- 8:14if you're an application developer you
- 8:15need to make sure that all of the inputs
- 8:17to your application are checked to make
- 8:19sure that a user can't add their own
- 8:21script to any of these input
- 8:28fields
About this transcript
This page contains the full transcript of Cross-site Scripting - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 1,485 words across 232 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.