Chapter 8: Cross-Site Scripting
Cross-site scripting is still one of the widespread vulnerabilities in web applications today. Also known as XSS, it is a security flaw that allows an attacker to insert malicious client-side code into an ASP.NET Core web page. The injected input is made possible because of the lack of sanitization and filtering, and the browser processes the unwanted arbitrary code.
An unknowing user can view a vulnerable web page in an XSS attack where the malicious script runs in the browser. Once the code executes, the attacker can potentially redirect the user to a rogue website, potentially steal its session cookies, or deface your ASP.NET Core web application.
In this chapter, we're going to cover the following recipes:
- Fixing reflected XSS
- Fixing stored/persistent XSS
- Fixing DOM XSS
By the end of this chapter, you will learn how to protect your ASP.NET Core web application from the different types of XSS by properly encoding...