Repository logo
Communities & Collections
Research Outputs
Fundings & Projects
People
Statistics
New user? Click here to register.Have you forgotten your password?
  1. Home
  2. KMITL
  3. Publication
  4. Protecting cookies from cross site script attacks using dynamic cookies rewriting technique
Loading...
Thumbnail Image

Protecting cookies from cross site script attacks using dynamic cookies rewriting technique

Author(s)
Putthacharoen, Rattipong
Bunyatnoparat, Pratheep
Date Issued
May 11, 2011
Type
Conference Paper
Abstract
Web applications often use cookies for maintaining an authentication state between users and web applications, these cookies are typically sent to the users by the web applications after the users have been successfully authenticated. Every subsequent request that contains the valid cookies will be automatically allowed by the web applications without any further authentication. The cookies are used to both identify and authenticate the users; therefore they are an interesting target for potential attackers. Cross Site Scripting attack (XSS for short) is one of popular attacks which is often used to steal the cookies from a browser's database. In this paper, we introduce a new technique called "Dynamic Cookies Rewriting", this technique aims to render the cookies useless for XSS attacks. Our technique is implemented in a web proxy where it will automatically rewrite the cookies that are sent back and forth between the users and the web applications. With our technique in place, the cookies at the browser's database now are not valid for the web applications; therefore the XSS attack will not be able to impersonate the users using stolen cookies. © 2011 Global IT Research Inst.
Citation
International Conference on Advanced Communication Technology Icact, 1090-1094, 2011
Subjects

Cookies

Cross Site Script Att...

HTTP and HTTPs

Web Proxy

Metrics
Get Involved!
  • Source Code
  • Documentation
  • Slack Channel
Make it your own

DSpace-CRIS can be extensively configured to meet your needs. Decide which information need to be collected and available with fine-grained security. Start updating the theme to match your Institution's web identity.

Need professional help?

The original creators of DSpace-CRIS at 4Science can take your project to the next level, get in touch!

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Accessibility settings
  • Privacy policy
  • End User Agreement
  • Send Feedback