NodeXP: NOde.js server-side JavaScript injection vulnerability DEtection and eXPloitation

Journal of Information Security and Applications(2021)

引用 10|浏览10
暂无评分
摘要
Web applications are widely used, and new ways for easier and cost-effective methods to develop them are constantly introduced. A common omission among the new development and implementation techniques when designing them is security; Node.js is no exception, as Server-Side JavaScript Injection (SSJI) attacks are possible due to the use of vulnerable functions and neglecting to sanitize data input provided by untrusted sources. This specific kind of injection attack stands out because it has the potential to compromise servers, where the JavaScript code is executed.
更多
查看译文
关键词
Code injection,Server-Side Javascript Injection,Detection,Exploitation,Deep learning,Node.js
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要