Loading…
AppSecUSA 2015 has ended
AppSecUSA 2015 - Buy ticket at http://2015.appsecusa.org/buy/
 
Back To Schedule
Friday, September 25 • 3:00pm - 3:55pm
New Methods in Automated XSS Detection: Dynamic XSS Testing without Using Static Payloads

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

For the past 15+ years all major automated XSS detection methods rely on payloads. Payloads are static exploit strings with previously known variations of exploits and exploit syntaxes. This presentation shows examples dynamic methods that do not rely on payloads to figure out if an XSS vulnerability exists. Furthermore these methods can be extended to provide, for the first time, accurate Stored XSS detection and generate dynamic custom XSS exploits. This presentation will show the current well-known automated XSS detection methods and the short comings of using a static payload methodology. It will then describe a number of methods and techniques that are used to provide dynamic XSS analysis. Finally, it will demonstrate how to create dynamic custom XSS exploits based on the dynamic detection XSS method described earlier in the presentation.

Speakers
avatar for Ken Belva

Ken Belva

Owner, XSS Warrior, LLC
I'm an almost 20 year cyber security veteran. AppSecUSA 2015 presenter. :) Please speak with me about opportunities for my XSS tool xssWarrior as well as Pen Testing services.


Friday September 25, 2015 3:00pm - 3:55pm PDT
Room C