Invention Grant
- Patent Title: Method, apparatus, terminal and media for detecting document object model-based cross-site scripting attack vulnerability
-
Application No.: US15034363Application Date: 2014-10-10
-
Publication No.: US09754113B2Publication Date: 2017-09-05
- Inventor: Jiacai Weng
- Applicant: TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED
- Applicant Address: CN Shenzhen, Guangdong
- Assignee: Tencent Technology (Shenzhen) Company Limited
- Current Assignee: Tencent Technology (Shenzhen) Company Limited
- Current Assignee Address: CN Shenzhen, Guangdong
- Agency: Harness, Dickey & Pierce, P.L.C.
- Priority: CN201310554402 20131108
- International Application: PCT/CN2014/088283 WO 20141010
- International Announcement: WO2015/067114 WO 20150514
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/57 ; G06F21/55

Abstract:
Disclosed are a method and apparatus for detecting a document object model (DOM) based cross-site scripting (XSS) vulnerability, an apparatus thereof, and a terminal are provided. The method includes: obtaining a set of parameter-value pairs from an original web address of a web page, where the set of parameter-value pairs comprises at least one parameter-value pair; replacing a parameter value in a parameter-value pair with feature code, to form a test web address for the web page, where the feature code comprises malicious code that comprises a malicious character and is uniquely identified in a DOM tree of the web page; obtaining page content corresponding to the test web address; converting the page content, into the DOM tree; and detecting whether a XSS vulnerability exists in the parameter-value pair, based on the DOM tree and the feature code.
Public/Granted literature
Information query