douxian5076 2012-04-08 03:15
浏览 77
已采纳

如何定位特定的XSS孔?

Recently i have noticed some strange stuff. In every public JavaScript file on my website there has been added redirect script at the end of every file.

I have access to access.logs and all that stuff.

How to locate trough what method did people insert this stuff?

How did they been able to access write permission on all my JavaScript files?

  • 写回答

1条回答 默认 最新

  • doulan4939 2012-04-08 03:27
    关注

    Since your JavaScript file has been changed, I don't think that's a XSS vulnerability.

    I think they have hacked in your web server, maybe your web application has some upload vulnerability, or your web server has some 0-day vulnerabilities.

    There are lots of ways to do that.

    Check your web server's file system, what's the time stamp that the JavaScript files have been modified? And which user had the permission to access those files?

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 Vue3 大型图片数据拖动排序
  • ¥15 划分vlan后不通了
  • ¥15 GDI处理通道视频时总是带有白色锯齿
  • ¥20 用雷电模拟器安装百达屋apk一直闪退
  • ¥15 算能科技20240506咨询(拒绝大模型回答)
  • ¥15 自适应 AR 模型 参数估计Matlab程序
  • ¥100 角动量包络面如何用MATLAB绘制
  • ¥15 merge函数占用内存过大
  • ¥15 使用EMD去噪处理RML2016数据集时候的原理
  • ¥15 神经网络预测均方误差很小 但是图像上看着差别太大