Тёмный

Cross-Site Scripting Explained with Examples and How to Prevent XSS with Content Security Policy 

Hussein Nasser
Подписаться 413 тыс.
Просмотров 56 тыс.
50% 1

In this video, I discuss XSS Cross-Site scripting attacks and how to prevent them.
0:00 Intro
2:40 XSS Stored Attacks
The injected script is stored permanently on the target servers. The victim then retrieves this malicious script from the server when the browser sends a request for data.
4:50 Reflected XSS Attacks
When a user is tricked into clicking a malicious link, submitting a specially crafted form, or browsing to a malicious site, the injected code travels to the vulnerable website. The Web server reflects the injected script back to the user's browser, such as in an error message, search result, or any other response that includes data sent to the server as part of the request. The browser executes the code because it assumes the response is from a "trusted" server which the user has already interacted with.
8:00 Source Code Explained
9:50 Prevent XSS Attacks with CSP
16:00 Prevent all scripts with CSP
Source Code
github.com/hnasr/javascript_p...
🏭 Backend Engineering Videos
• Backend Engineering (B...
💾 Database Engineering Videos
• Database Engineering
🛰 Network Engineering Videos
• Network Engineering
🏰 Load Balancing and Proxies Videos
• Proxies
🐘 Postgres Videos
• PostgresSQL
🚢Docker
• Docker
🧮 Programming Pattern Videos
• Programming Patterns
🛡 Web Security Videos
• Web Security
🦠 HTTP Videos
• HTTP
🐍 Python Videos
• Python by Example
🔆 Javascript Videos
• Javascript by Example
👾Discord Server / discord
Become a Member
/ @hnasr
Support me on PayPal
bit.ly/33ENps4
Become a Patreon
/ hnasr
Stay Awesome,
Hussein

Наука

Опубликовано:

 

5 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 99   
@galfrasian
@galfrasian 4 года назад
Love your spirit man. You keep regularly updating your videos. Great job.
@hnasr
@hnasr 4 года назад
Saumya yadav ❤️
@asderex
@asderex 4 года назад
Great video Hussein. I’ve heard of XSS but never had them explained so clearly. Would love to see more security related videos if the inspiration hits you! This has become my favourite back end channel - thanks for your effort making these.
@hnasr
@hnasr 4 года назад
Thanks for the encouragement ❤️ well sure keep them coming whenever Inspiration hits. I put all my security related videos on this playlist. Check it out ru-vid.com/group/PLQnljOFTspQU3YDMRSMvzflh_qXoz9zfv
@TheMessanger
@TheMessanger 2 года назад
@@hnasr Wao I just saw the playlist this is overwhelming!
@DennisIvy
@DennisIvy 3 года назад
Great video Hussein!
@NishaJakhar26
@NishaJakhar26 3 года назад
Oooooo Mama......... :D Your Accent/tone/speech/words/humor is just perfect. Thank you that i found you.
@hnasr
@hnasr 3 года назад
Oh thank you!
@user-mb9vk8vq8w
@user-mb9vk8vq8w 7 месяцев назад
0:34 😂😅
@dean6046
@dean6046 4 года назад
Thanks man! You've been shooting out amazing content lately like multiple times a week! Keep up the good work
@hnasr
@hnasr 4 года назад
Constantine thanks whenever I feel inspired I put some content out before the inspiration dies. 😊 I love making videos
@dean6046
@dean6046 4 года назад
@@hnasr I appreciate the answer! I have to change my mindset about making content and use your philosophy. I make a lot of content but I just keep trying to perfect it so I never release anything publicly.
@hnasr
@hnasr 4 года назад
You should release your work! You have no idea who your work will help 🙏
@jakealert1722
@jakealert1722 4 года назад
Another Hussein Nasser video woohoooo! Would be really awesome if you could make a video purely about CSP. How to set it up and what the best practices are :)
@virendrabhati6685
@virendrabhati6685 3 года назад
Wow!! Very informative. I lean new things again in less time.... It will help me a lot to prevent outside to come in to my server scripts.
@tech3425
@tech3425 Год назад
Mahn! Incredibly fun to watch! Love your content bro
@urmur
@urmur 2 года назад
this is so easily digestable! thank you
@potaraju92
@potaraju92 3 месяца назад
Love your style of teaching, man, you are awesome.
@subhajitshome2175
@subhajitshome2175 3 года назад
Thank you Naseer ! This is very helpful
@Lena-of7wd
@Lena-of7wd 2 года назад
Great explanation, thanks!
@paschalokafor9043
@paschalokafor9043 6 месяцев назад
I just subscribed. You are awesome bro. Thank you loads.
@Wojmasz
@Wojmasz 4 года назад
Thank you very much and keep doing your job :)
@HayBeseret
@HayBeseret 4 года назад
FYI - its a "reflected" since your code is "reflecting" the search item on the return results page @2:24, thus executing the script.
@tomytoon123
@tomytoon123 7 месяцев назад
I enjoy how this guy explain :)
@CyberSecForce
@CyberSecForce 2 года назад
We appreciate your efforts
@mysticaltech
@mysticaltech 3 года назад
Awesome made it all clearer 🙏
@usamatahseenulhaque9125
@usamatahseenulhaque9125 4 года назад
You are the best explainer
@sariksiddiqui6059
@sariksiddiqui6059 4 года назад
This is cool man.I was on facebook console doing all things and kept getting this CSP thing, glad you cleared it up.Need to see how to implement it in nginx when delivering static website
@hnasr
@hnasr 4 года назад
Siddiqui Sarik should be as simple as adding that header assuming your nginx is layer 7 reverse proxying
@ganeshk5471
@ganeshk5471 Год назад
Hello Hussein after going through video , I realised that it was you . I have watched most of your content on the design
@danielrocha5774
@danielrocha5774 2 года назад
thanks for the nice explaining it was very enjoyable.
@taytot3283
@taytot3283 3 года назад
This was incredibly helpful thank you! How does this work with the HTML tag "meta http-equiv="Content-Security-Policy" content="default-src 'self'"? Does this tag mean I don't have to include all the lines of JS shown in your video?
@TheMessanger
@TheMessanger 2 года назад
I hope he answers looks like you may be missing code
@immanuel7619
@immanuel7619 2 года назад
It's very informative!
@inderkantkhandelwaal3402
@inderkantkhandelwaal3402 Год назад
Great Explanation
@rahul.r
@rahul.r 4 года назад
Glad to see you actively adding more videos. Trying to watch as many as possible. Can we expect a video on tools like Prometheus and Grafana by any chance?
@hnasr
@hnasr 4 года назад
Rahul it is on my list of things to research.
@rahul.r
@rahul.r 4 года назад
Hussein Nasser great to hear that!
@ca7986
@ca7986 4 года назад
Please make more videos on web security and headers! ❤️
@harshpatel9742
@harshpatel9742 3 года назад
This is $$ Gold $$. Thank you so much. You earned a subscriber!
@hnasr
@hnasr 3 года назад
Awesome, thank you! :D
@AssFaceNFT
@AssFaceNFT 2 года назад
Very helpful ser!! 🙏🌹❤
@norah5073
@norah5073 Год назад
I love your videos always you are the best on youtube Thank you so much for your effort and time
@samueladewale2987
@samueladewale2987 4 года назад
Thank you for this great video, as always. Learning a lot from them. (I am trying to build a resource server for my spring boot- anugular application. Please do you know any resource that will help or any free tool I can use. Thanks for your feedback.)
@sigmamoon7067
@sigmamoon7067 2 года назад
Awesome Demo thank's
@anushahd673
@anushahd673 3 года назад
It was helpful, thank you
@hnasr
@hnasr 3 года назад
Glad to hear that!
@mubin986
@mubin986 2 года назад
ও মামা। Amazing explanation!
@umeshb8210
@umeshb8210 3 года назад
Thank you for a beautiful explanation sir. Actually interested in learning js btw found u on Udemy.
@hnasr
@hnasr 3 года назад
NO Oxygen thank you for your comments I hope you enjoy the content and welcome to the channel
@mayurpatil7356
@mayurpatil7356 3 года назад
Such powerful stuff...
@ch94086
@ch94086 4 года назад
Of course you could have mentioned the real problem and solution in the js code, distinguishing text from HTML encoded text. (Easier with typescript 😜) But good demo of the csp header.
@zaylo9273
@zaylo9273 3 года назад
if it is a dynamic website, is it okay to put the main homepage link in?
@dmitry.gashko
@dmitry.gashko 3 года назад
4:55 In general stored xss is more dangerous than reflected one. First - there are no user action required to run a stored xss (when a reflected xss needs a link) and second - any stored xss can also be used as a reflected xss. I mean, I can make some xss on a page no one goes to, so stored xss is not so dangerous there, but I still can make a link to that page, like with reflected xss. But, what I was thinking about, is that stored xss is more dangerous on public pages but on private pages reflected xss is more dangerous . This is because stored xss on private pages in most cases is like self xss - you make that xss, and you can "hack" yourself, but with reflected xss on private pages you can send a link to, for example, profile settings, and it would be quite regular reflected xss. p.s. of course there's always an ability that admins can go to private pages, so, any stored/reflected xss is bad and no matter where it appeared.
@TheMessanger
@TheMessanger 2 года назад
I need a coder like you trying to login into a scam site. I got my login but I want full access!
@NeMoZz1000
@NeMoZz1000 3 года назад
شكرا جدا عالشرح الواضح
@hnasr
@hnasr 3 года назад
❤️❤️ العفو
@rajath1964
@rajath1964 4 года назад
is XSS relevant to only public domain sites(twitter,facebook) or even licensed webapps(jira, enterprise git..etc) can undergo XSS?
@dmitry.gashko
@dmitry.gashko 3 года назад
XSS is relevant to WEB in general. So, no matter jira is, github, gitlab, youtube or amazon.
@amarbalu109
@amarbalu109 3 года назад
Hi Hussain.Your content is awesome. Csp attributes get fails even though it has been configured correct url.can u help me out?
@debugmedia
@debugmedia 4 года назад
"Oooo Mama" 😂 - Hussain 2020
@vishalksahoo3599
@vishalksahoo3599 Год назад
Anybody know how to check if a given website has xss header enabled using pyhton.
@myjava2844
@myjava2844 3 года назад
hi hussein I need you help/info related to one issue We have in java code like below String hname = request.getRemoteName(); // this line is showing issue in Fortify scan can you help me how to validate the hname? I used with ESAPI input validator but it could not remediate it. Please help
@azamatabdullaev4580
@azamatabdullaev4580 2 года назад
awesome
@thegreatkris24
@thegreatkris24 9 месяцев назад
What websites let you just store things on them like that?
@god_ofdestruction7355
@god_ofdestruction7355 2 года назад
Does xss protection header prevents DOM xss
@natesh1
@natesh1 4 года назад
At 09:13 , you said we shoudnt write script inside inline script tag. But it wasn't clear why. Can u elaborate on it please.
@hnasr
@hnasr 4 года назад
Natesh M Bhat Because most cross side scripting attacks uses inline script injunction too. So the best approach is to block inline script and use CSP to only load it from a url. As i explained in the end
@debugmedia
@debugmedia 4 года назад
I don't know if u use instagram but there was this one account who posted an insta story, It said "Some text" and below was the profile picture of the person who was viewing that story. So if i opened the story then it would be my pic. But Instagram doesnt provide any API like RU-vid does even if it did , There isn't any place to embed it. I wonder how he did it cuz it was pretty cool
@leocarvalho8051
@leocarvalho8051 4 года назад
what account is that?
@rahuldora1587
@rahuldora1587 3 года назад
I have also seen that one of my friend gave that link to view that status and there is a image placeholder where profile pic of the status viewer will be shown
@FordExplorer-rm6ew
@FordExplorer-rm6ew 4 года назад
Been just kind of defeated. Haven't even been on a computer in a long time. I do like your vids though. Still picking up theories and concepts here and there
@hnasr
@hnasr 4 года назад
sry828 89 it takes time I feel the same sometimes too because of the amount of information out there. I find it helpful to know that this is a marathon not sprint and I just take things easy and only jump on things that interests me. That doesn’t always happen though like today I just spent the whole day relaxing, playing video games and grilling. No engineering 😅
@FordExplorer-rm6ew
@FordExplorer-rm6ew 4 года назад
@@hnasr thankgs for the encouragement. Noted and definitely appreciated Thx fren :) 👍
@Cdswjp
@Cdswjp 2 года назад
great
@natesh1
@natesh1 4 года назад
Can u make a vid on modsecurity with Nginx
@sharadshinde9101
@sharadshinde9101 2 года назад
How to implement in struts
@ca7986
@ca7986 4 года назад
❤️
@hardikmistry1661
@hardikmistry1661 2 года назад
the edvotise was so greate "click here to Boost your CPU"🤣🤣🤣
@semirberisha
@semirberisha Год назад
So you mean that if we do use CSP XSS can't be injected, right ?
@hnasr
@hnasr Год назад
they can be injected, they just won’t be triggered if inline script is disabled
@semirberisha
@semirberisha Год назад
@@hnasr I am not getting it. So the final answer is: It can't be hcaked, right ?
@earl_the_great
@earl_the_great 3 года назад
When your mom found out that you did something wrong and she stares at you like she about to end yo career: 3:26
@hunterone7072
@hunterone7072 3 года назад
joss
@stacyobiero
@stacyobiero 3 года назад
XSS babes!
@netman87
@netman87 4 года назад
This + html ping to post form :)
@CandiceKhannaApps
@CandiceKhannaApps 2 года назад
Thank you for saying SHE and including us ✨ 🙌🏽 ✨ women hack & code too (:
@tigreytigrey8537
@tigreytigrey8537 Год назад
Oh God STFU up with that dumb brainwashed crap.
@tigreytigrey8537
@tigreytigrey8537 Год назад
Learn to be a damn adult already.
@taruncharan4262
@taruncharan4262 2 года назад
alert("Mad")
@DevinJohw
@DevinJohw 2 месяца назад
alert("Hello");
@kambalavijay6800
@kambalavijay6800 3 года назад
alert(test attack);
@beastern1807
@beastern1807 3 года назад
Forgot the quotes for the string
@Adarsh-Shrivastava
@Adarsh-Shrivastava 6 месяцев назад
alert("XSS")
@Adarsh-Shrivastava
@Adarsh-Shrivastava 6 месяцев назад
This proves youtube comments os safe from XSS
Далее
Content-Security-Policy: An Introduction
30:28
Просмотров 40 тыс.
КОРОЧЕ ГОВОРЯ, ШКОЛА БУДУЩЕГО
10:40
Cross Site Request Forgery - Computerphile
9:20
Просмотров 757 тыс.
DO NOT USE alert(1) for XSS
12:16
Просмотров 163 тыс.
Proxy vs Reverse Proxy Server Explained
14:18
Просмотров 129 тыс.
Cross-Site Scripting (XSS) Explained And Demonstrated!
8:54