Invention Grant
- Patent Title: Using encoding to detect security bugs
- Patent Title (中): 使用编码来检测安全漏洞
-
Application No.: US12410482Application Date: 2009-03-25
-
Publication No.: US08332821B2Publication Date: 2012-12-11
- Inventor: Spencer Wong Low , Daniel W. Crevier
- Applicant: Spencer Wong Low , Daniel W. Crevier
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Main IPC: G06F9/44
- IPC: G06F9/44

Abstract:
A system that facilitates detecting security flaws in a web site that receives and transmits untrusted content is described herein. The system includes a receiver component that receives test content that corresponds to a field on a web page that, when the web site is online, is configured to receive user-generated content, wherein the test content includes non-malicious data. An encoder component encodes each character of the test content regardless of form or content of the test content to generate encoded content. A display component displays encoded content and non-encoded content of the web page to a tester on a computer screen, wherein the display component causes the encoded content to be displayed in a visually distinct manner from the non-encoded content.
Public/Granted literature
- US20100251216A1 USING ENCODING TO DETECT SECURITY BUGS Public/Granted day:2010-09-30
Information query