XSS Attack Vectors
Web applications are vulnerable to Cross-Site Scripting (XSS) attacks, where attackers inject malicious scripts into web pages viewed by other users. XSS can be categorized into three primary attack vectors: stored, reflected, and DOM-based. Each vector exploits different stages of the request-response cycle and requires distinct mitigation strategies. Understanding these vectors is critical for identifying and defending against XSS vulnerabilities.
Stored XSS (Persistent XSS)¶
Definition: Malicious scripts are stored permanently on the target server (e.g., in databases, comment sections, or user profiles). These scripts are executed whenever users access the affected page.
Attack Vector:
- The attacker submits malicious input (e.g., a script) to a server-side endpoint that stores data without proper sanitization.
- When other users load the page, the stored script is rendered in their browser, executing arbitrary code.
Example:
A user submits a comment containing <script>alert('XSS')</script>. If the server stores this comment without escaping, it will execute the script for all subsequent visitors.
Command/Example:
Reflected XSS (Non-Persistent XSS)¶
Definition: Malicious scripts are embedded in HTTP requests (e.g., URLs, form data) and reflected back to the user’s browser without proper validation.
Attack Vector:
- The attacker crafts a malicious URL or form input containing a script.
- The victim unknowingly visits the URL or submits the form, causing the browser to execute the script.
Example:
A search query like https://example.com/search?q=<script>alert('XSS')</script> reflects the payload in the response, triggering the script when the page loads.
Command/Example:
# Craft a malicious URL to exploit reflected XSS
curl "https://vulnerable-site.com/search?q=<script>alert('XSS')</script>"
DOM-Based XSS¶
Definition: Malicious scripts manipulate the Document Object Model (DOM) via client-side code (e.g., JavaScript), often without server involvement.
Attack Vector:
- The attacker injects a script that modifies the DOM based on user input (e.g., URL parameters or JavaScript variables).
- The script executes in the victim’s browser, bypassing server-side validation.
Example:
A URL like https://example.com/page?param=<script>alert('XSS')</script> triggers a script that writes the payload to the DOM:
Command/Example:
// DOM-based XSS payload in a script tag
<script>
const userInput = window.location.hash;
document.body.innerHTML = userInput;
</script>
Key takeaways¶
- Stored XSS relies on persistent storage of malicious scripts, while reflected XSS depends on immediate reflection in HTTP responses.
- DOM-based XSS exploits client-side code to manipulate the DOM, often evading server-side sanitization.
- Common delivery mechanisms include URL parameters, form inputs, and stored data, requiring strict input validation and context-aware escaping.
- Always sanitize user input, escape outputs, and avoid dynamic DOM manipulation without validation.