Invention Grant
- Patent Title: Cross-site scripting prevention in dynamic content
- Patent Title (中): 动态内容中的跨站点脚本预防
-
Application No.: US12899255Application Date: 2010-10-06
-
Publication No.: US08910247B2Publication Date: 2014-12-09
- Inventor: Michael Andrews , Sharat Shroff , Dennis Gursky , Melissa Lauren Benua
- Applicant: Michael Andrews , Sharat Shroff , Dennis Gursky , Melissa Lauren Benua
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Dave Ream; Sade Fashokun; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/62 ; G06F17/30 ; G06F21/52

Abstract:
Embodiment relate to systems, methods, and computer storage media for suppressing cross-site scripting in a content delivery system. A request is received for content that includes a scripted item or scripted items. The scripted item is identified within the content. An identifier is associated with the scripted element when the scripted element is an intended scripted element to be associated with the content. The identifier may be a hash value based from a hash function and the scripted item. Prior to communicating the content to a user, the scripted item is identified again to determine if an identifier is associated with the scripted item. If an identifier is associated with the scripted item, the identifier is evaluated to determine if the identifier is appropriate. When the identifier is determined to not be appropriate, the scripted item is prevented from being communicated to a user.
Public/Granted literature
- US20120090026A1 CROSS-SITE SCRIPTING PREVENTION IN DYNAMIC CONTENT Public/Granted day:2012-04-12
Information query