YouTube2Text

Cross-site Scripting - CompTIA Security+ SY0-701 - 2.3 — Transcript

by Professor Messer · 1,485 words · 232 segments · language en · Watch on YouTube

Full transcript

  1. 0:02in this video we'll talk about
  2. 0:03cross-site scripting and you may see
  3. 0:05this also abbreviated as
  4. 0:07xss it seems like we would use the
  5. 0:09abbreviation CSS for cross-site
  6. 0:12scripting but that abbreviation has
  7. 0:14already been taken by cascading
  8. 0:16stylesheets so instead we use xss to be
  9. 0:19able to differentiate between both of
  10. 0:21those Technologies this attack type was
  11. 0:23originally called cross-site scripting
  12. 0:25because of vulnerabilities that we found
  13. 0:28inside of our browsers these vulner IL
  14. 0:30is created a situation inside of your
  15. 0:32browser where information from one site
  16. 0:34could be shared with another site crossy
  17. 0:37scripting is one of the most common
  18. 0:39vulnerabilities for web-based
  19. 0:40applications this takes advantage of the
  20. 0:43trust that the browser has for different
  21. 0:45websites although there are challenges
  22. 0:47in creating a cross-site scripting
  23. 0:48exploit once you have that exploit there
  24. 0:51are many different ways to take
  25. 0:52advantage of it many of these cross-side
  26. 0:55scripting vulnerabilities are based
  27. 0:56around an attack using JavaScript
  28. 0:59JavaScript scpt is a very popular
  29. 1:01scripting language within our browsers
  30. 1:03and practically everyone has JavaScript
  31. 1:05enabled in their
  32. 1:07browser from a high level let's see how
  33. 1:09a cross-side scripting attack might be
  34. 1:11exploited let's start with the victim
  35. 1:13that would be our system a trusted
  36. 1:15website that we might commonly associate
  37. 1:18with and of course there is the attacker
  38. 1:20one way that you could exploit a
  39. 1:22cross-site scripting vulnerability is
  40. 1:24for the attacker to send a link to the
  41. 1:25victim that has a malicious script
  42. 1:28inside of it this could be sent over
  43. 1:30email it might be a text message or any
  44. 1:32other method that would get that
  45. 1:34malicious link into the hands of the
  46. 1:36victim the victim will click the link
  47. 1:38inside of that message which takes them
  48. 1:40to a legitimate site and it's one that's
  49. 1:42trusted by the victim but because the
  50. 1:45attacker has provided this link there's
  51. 1:47additional information included with
  52. 1:49this connection usually it's a malicious
  53. 1:51script that's also running along with
  54. 1:54the connection to the trusted website
  55. 1:56this malicious script is not usually
  56. 1:57seen by the victim but behind the scenes
  57. 1:59means there's data that's being sent
  58. 2:01directly to the attacker this might
  59. 2:03include cookie information session
  60. 2:05details other specifics on that
  61. 2:07particular website and anything else
  62. 2:09that may be considered private or secure
  63. 2:12information one common type of a
  64. 2:14cross-site scripting attack is a
  65. 2:16non-persistent attack this might also be
  66. 2:19called a reflected attack this is one
  67. 2:21where a third-party website might be
  68. 2:24configured in a way that would allow
  69. 2:26people to run scripts inside of these
  70. 2:28user input blocks a website like this
  71. 2:31one providing a search engine should not
  72. 2:33allow someone to run their own
  73. 2:35JavaScript within that input box that's
  74. 2:38exactly what has been found here by an
  75. 2:40attacker the attacker is going to email
  76. 2:42that link that takes advantage of that
  77. 2:44vulnerability and behind the scenes that
  78. 2:46script is going to send those private
  79. 2:48details to the attacker so the attacker
  80. 2:50is the one sending the malicious code to
  81. 2:52the user but the user is the one
  82. 2:54executing that malicious code against a
  83. 2:57thirdparty website the thirdparty
  84. 2:59website May send session ID information
  85. 3:01to the attacker which means the attacker
  86. 3:03will now have the same access to that
  87. 3:05thirdparty website as the victims's
  88. 3:08machine here's an example of a website
  89. 3:10that has a cross-site scripting
  90. 3:11vulnerability this is one that has a
  91. 3:13shopping cart in it you can see there
  92. 3:15are a number of items within the
  93. 3:16shopping cart and on this particular
  94. 3:18site it's the credit card number field
  95. 3:20that does not do any type of checking
  96. 3:22for scripts which means we could embed a
  97. 3:25script within that credit card number
  98. 3:27field to be able to perform this cross
  99. 3:29site scripting attack so here I've
  100. 3:31created a very small amount of
  101. 3:33JavaScript it's a very simple script
  102. 3:35that simply puts an alert message on the
  103. 3:37screen and that alert message shows your
  104. 3:40session information and then the session
  105. 3:42ID within the cookie for this site so
  106. 3:45when we're putting in credit card
  107. 3:46information we would also include that
  108. 3:48entire script along with the credit card
  109. 3:50details and you can see we've pasted it
  110. 3:52in on that credit card field when we
  111. 3:55click the purchase button a message
  112. 3:56appears on the screen with the
  113. 3:58information about our session and it
  114. 4:00includes the session ID now obviously
  115. 4:03the attacker is not going to have a
  116. 4:05session ID message pop up on your screen
  117. 4:07instead that session ID will be sent
  118. 4:09directly to the attacker behind the
  119. 4:11scenes and the victim has no idea that
  120. 4:13that session information is now in the
  121. 4:15hands of the
  122. 4:17attacker instead of the attacker trying
  123. 4:19to find some specific way to directly
  124. 4:22send a link to a user what if the
  125. 4:25attacker simply posted the link on
  126. 4:27Facebook this is the idea behind a
  127. 4:29persistent or stored cross-site
  128. 4:31scripting attack the attacker will post
  129. 4:33a message on a social media site and it
  130. 4:36will include with that message the
  131. 4:38malicious payload which is probably
  132. 4:40malicious JavaScript this is why it's
  133. 4:42now called persistent because the
  134. 4:44attacker has now stored that information
  135. 4:47on that thirdparty social networking
  136. 4:49site everyone who visits that page with
  137. 4:51the malicious software will effectively
  138. 4:54have that code run inside of their
  139. 4:55browser from the attacker perspective
  140. 4:58this means that they're effectively
  141. 4:59attacking everyone who visits that
  142. 5:01social networking page so all of the
  143. 5:04viewers of that information will have
  144. 5:06that JavaScript run inside of their
  145. 5:08local browser and because this is a
  146. 5:10social networking site the attacker
  147. 5:12might include other code that would
  148. 5:14allow people to share their malicious
  149. 5:16code so anyone who views this message
  150. 5:19can have it posted to their own feed on
  151. 5:21that social media site and the next
  152. 5:23person that views it on their feed goes
  153. 5:25through the exact same process and again
  154. 5:28and again as this m message is now
  155. 5:30spread to all of these different users
  156. 5:32using a persistent or stored cross-site
  157. 5:35scripting attack an interesting crossy
  158. 5:37scripting attack was found in June 2017
  159. 5:40by Aon Guzman he's a security researcher
  160. 5:43who is looking at the Subaru front end
  161. 5:46on their website that allows them to
  162. 5:48manage different capabilities within
  163. 5:50their vehicle when you log into the
  164. 5:52Subaru website you get a token and this
  165. 5:55token never expires which from a best
  166. 5:58practices perspective I is probably not
  167. 6:00the best idea normally there would be
  168. 6:02some expiration for instance the token
  169. 6:05might expire in a day which would
  170. 6:06require you to log in again after 24
  171. 6:09hours Not only was there no expiration
  172. 6:12associated with this token the token
  173. 6:14allowed you to perform any service
  174. 6:16request on your vehicle not only did
  175. 6:18this create a security concern for your
  176. 6:20vehicle but you could add your email
  177. 6:22address to someone else's account and
  178. 6:25the same token would allow you access
  179. 6:27into managing their veh vehicle as well
  180. 6:30the cross-site scripting part of this is
  181. 6:32a vulnerability that was also on the
  182. 6:34Subaru website which means an attacker
  183. 6:37could send a link with malicious code
  184. 6:39inside of it and receive the token for
  185. 6:42that particular Subaru website from the
  186. 6:44victim and now since we know that this
  187. 6:46token has such power as soon as the
  188. 6:49attacker has that copy of a user's token
  189. 6:52they're able to use it forever because
  190. 6:54the token doesn't expire and if the
  191. 6:55attacker adds their email address to
  192. 6:58another Subaru account that same token
  193. 7:00will also grant them access to that
  194. 7:03account this is effectively a single
  195. 7:05token that allows an attacker full
  196. 7:07access to anyone's vehicle that may be
  197. 7:10registered on the Subaru website
  198. 7:12fortunately this particular
  199. 7:13vulnerability was found by a security
  200. 7:15researcher who informed Subaru of the
  201. 7:17issue and they were able to resolve and
  202. 7:20remove these
  203. 7:21vulnerabilities there's a few things we
  204. 7:23can do to protect ourself against a
  205. 7:25cross-site scripting attack one of these
  206. 7:28is to not click a link that you may not
  207. 7:30already trust you should not click links
  208. 7:32inside of your email your messages or
  209. 7:35anything else that's coming from a third
  210. 7:37party instead you should open a browser
  211. 7:39separately and only type in domain names
  212. 7:42that you can trust you may want to
  213. 7:44consider either disabling JavaScript or
  214. 7:47limiting the capabilities of JavaScript
  215. 7:49sometimes you can do that with a browser
  216. 7:51plug-in but this offers limited
  217. 7:53protection and ultimately it may limit
  218. 7:55what website you're able to visit
  219. 7:57perhaps most importantly you should
  220. 7:59always make sure that your browser and
  221. 8:01your applications are always updated to
  222. 8:03the latest version as manufacturers
  223. 8:05locate and identify these cross-site
  224. 8:07scripting vulnerabilities they will push
  225. 8:09out patches to prevent your browser from
  226. 8:11being susceptible to these problems and
  227. 8:14if you're an application developer you
  228. 8:15need to make sure that all of the inputs
  229. 8:17to your application are checked to make
  230. 8:19sure that a user can't add their own
  231. 8:21script to any of these input
  232. 8:28fields

About this transcript

This page contains the full transcript of Cross-site Scripting - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 1,485 words across 232 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.