Invention Grant
- Patent Title: Persistent cross-site scripting vulnerability detection
-
Application No.: US16353795Application Date: 2019-03-14
-
Publication No.: US11005877B2Publication Date: 2021-05-11
- Inventor: Emanuel Bronshtein , Roee Hay , Sagi Kedmi
- Applicant: HCL Technologies Limited
- Applicant Address: IN New Delhi
- Assignee: HCL Technologies Limited
- Current Assignee: HCL Technologies Limited
- Current Assignee Address: IN New Delhi
- Agency: Brooks Kushman P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Various techniques for detecting a persistent cross-site scripting vulnerability are described herein. In one example, a method includes detecting, via the processor, a read operation executed on a resource using an instrumentation mechanism and returning, via the processor, a malicious script in response to the read operation. The method also includes detecting, via the processor, a write operation executed on the resource using the instrumentation mechanism and detecting, via the processor, a script operation executed by the malicious script that results in resource data being sent to an external computing device from a client device. Furthermore, the method includes receiving, via the processor, metadata indicating the execution of the read operation, the write operation, and the script operation.
Public/Granted literature
- US20190215333A1 PERSISTENT CROSS-SITE SCRIPTING VULNERABILITY DETECTION Public/Granted day:2019-07-11
Information query