US2016241588A1PendingUtilityA1
Methods for determining cross-site scripting and related vulnerabilities in applications
Individually held — no corporate assignee on recordPriority: Mar 15, 2014Filed: Apr 26, 2016Published: Aug 18, 2016
Est. expiryMar 15, 2034(~7.6 yrs left)· nominal 20-yr term from priority
Inventors:Kenneth F. Belva
H04L 63/1433G06F 2221/033H04L 63/1416G06F 21/577H04L 63/1466H04L 67/02
26
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
The invention provides computer-implemented methods and computer systems for testing applications such as web-based (HTTP) applications for cross-site scripting (XSS) and related security vulnerabilities and permits the discovery of previously unknown XSS and related vulnerabilities in applications without relying on known or previously generated static XSS signatures. The invention may be applied to any type of XSS or related vulnerability for any variation of application code.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method for testing an application for cross-site scripting vulnerabilities, comprising the steps of:
under control of at least one processor,
(a) for at least one field, parameter or Uniform Resource Locator (URL) of the application, submitting a request in which the field, parameter or URL contains a test slug consisting of an encoded or non-encoded test character or a string of test characters between two default slugs;
(b) determining when the application returns the test slug with the test character or string of test characters and whether any of the test characters in the test slug are transformed or not transformed in the returned test slug;
(c) storing in non-transitory computer memory the result of the determinations made in step (b); and
(d) repeating steps (a)-(c) for a plurality of different test characters or strings of test characters.
2 . The computer-implemented method of claim 1 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
3 . The computer-implemented method of claim 1 , further comprising the steps of:
before steps (a)-(d), for at least one field, parameter or URL of the application, submitting a request in which the parameter, field or URL contains a default slug not having any special characters; and determining when the application reflects the default slug without any transformation of characters in response to the request, wherein when the application returns the default slug without any transformation of characters, the test slug used in step (a) consists of the encoded or non-encoded test character(s) sandwiched between two default slugs which may be the same or different.
4 . The computer-implemented method of claim 3 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
5 . The computer-implemented method of claim 1 , wherein in step (a), the at least one field, parameter or Uniform Resource Locator (URL) of the application comprises a URL.
6 . The computer-implemented method of claim 5 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
7 . The computer-implemented method of claim 3 , wherein the submitting step performed before steps (a)-(d) comprises:
before steps (a)-(d), for at least one URL of the application, submitting a request in which the URL contains a default slug not having any special characters.
8 . The computer-implemented method of claim 7 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
9 . A computer system configured to test an application for cross-site scripting vulnerabilities, comprising:
at least one processor; non-transitory processor-accessible memory; and computer instructions stored in the non-transitory processor-accessible memory, said computer instructions configured to direct the at least one processor to perform the steps of: (a) for at least one field, parameter or Uniform Resource Locator (URL) of the application, submitting a request in which the field, parameter or URL contains a test slug consisting of an encoded or non-encoded test character or a string of test characters between two default slugs; (b) determining when the application returns the test slug with the test character or string of test characters and whether any of the test characters in the test slug are transformed or not transformed in the returned test slug; (c) storing in non-transitory computer memory the result of the determinations made in step (b); and (d) repeating steps (a)-(c) for a plurality of different test characters or strings of test characters.
10 . The computer system of claim 9 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
11 . The computer system of claim 9 , further comprising:
a communication module under control of the at least processor, the communications module configured to provide communication between the computer system and the application to be tested for cross-site scripting vulnerabilities by the computer system.
12 . The computer system of claim 11 , wherein the test character is a special character or at least one of the test characters of the string of test characters is a special character.
13 . The computer system of claim 9 , wherein the computer instructions are further configured to direct the at least one processor to perform the steps of:
before steps (a)-(d), for at least one field, parameter or URL of the application, submitting a request in which the parameter, field or URL contains a default slug not having any special characters; and determining when the application reflects the default slug without any transformation of characters in response to the request, wherein when the application returns the default slug without any transformation of characters, the test slug used in step (a) consists of the encoded or non-encoded test character(s) sandwiched between two default slugs which may be the same or different.
14 . The computer system of claim 10 , wherein the computer instructions are further configured to direct the at least one processor to perform the steps of:
before steps (a)-(d), for at least one field, parameter or URL of the application, submitting a request in which the parameter, field or URL contains a default slug not having any special characters; and determining when the application reflects the default slug without any transformation of characters in response to the request, wherein when the application returns the default slug without any transformation of characters, the test slug used in step (a) consists of the encoded or non-encoded test character(s) sandwiched between two default slugs which may be the same or different.
15 . The computer system of claim 11 , wherein the computer instructions are further configured to direct the at least one processor to perform the steps of:
before steps (a)-(d), for at least one field, parameter or URL of the application, submitting a request in which the parameter, field or URL contains a default slug not having any special characters; and determining when the application reflects the default slug without any transformation of characters in response to the request, wherein when the application returns the default slug without any transformation of characters, the test slug used in step (a) consists of the encoded or non-encoded test character(s) sandwiched between two default slugs which may be the same or different.
16 . The computer system of claim 12 , wherein the computer instructions are further configured to direct the at least one processor to perform the steps of:
before steps (a)-(d), for at least one field, parameter or URL of the application, submitting a request in which the parameter, field or URL contains a default slug not having any special characters; and determining when the application reflects the default slug without any transformation of characters in response to the request, wherein when the application returns the default slug without any transformation of characters, the test slug used in step (a) consists of the encoded or non-encoded test character(s) sandwiched between two default slugs which may be the same or different.Join the waitlist — get patent alerts
Track US2016241588A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.