Web applications attacks: HTML injection



HTML injection is a sort of injection bug that happens when an attacker is able to inject arbitrary HTML code into a vulnerable (unfiltered input) web page. This issue can have many results, such as the disclosure of a victim’s session cookies, or it can enable the attacker to change the page content that seen by many users.
it’s a basic security issue in which data (information like an email address or address or first name) and code (that build the web page, such as the creation of <script> elements) mix in unwanted ways.

An XSS attack rewrites the content of a web page or performs arbitrary JavaScript within the user’s web browser. This happens when a website gets some piece of data (text with HTML or JS code) from the user—an e-mail address, a user ID, a comment to a blog post, a status message, etc. and displays this data on a web page. If the site is not filtering the users inputs, then the meaning of the HTML document can be changed by a carefully crafted string.
This vulnerability is similar to Cross-site Scripting (XSS). Attacker finds an injection vulnerability and determines to use the vulnerability to hack some victims. The attacker will craft malicious link, including his injected HTML code, and send the malicious link to the victim.


Comments


  1. i read that and clarify my doubts very well.in this information i observe lot of things about how to study this technology.........thanks a lot
    ethical hacking in chennai
    ethical hacking training in coimbatore
    ethical hacking training in bangalore

    ReplyDelete
  2. SQL Injection is nowadays a dying problem in the web development community due to stricter coding and the mass use of popular open source projects like WordPress, but it is still definitely something that can not be ignored. Simple coding mistakes can cause a huge vulnerability to the entire site structure. prototype manufacturers usa

    ReplyDelete

  3. My life was falling apart, I was being cheated and abused, I had to know the truth and needed proof. I contacted a private investigator that linked me with onlineghost who took care of the hack job. He hacked his iPhone,Facebook,Instagram, Whats app, twitter and email account. I got all I wanted as proof . I”m glad i had a proven truth he was cheating . Contact him for any hack job. Tell him i referred you to him, he will surely meet your hack need. Contact: onlineghosthacker247@ gmail .com

    ReplyDelete
  4. Do you need to increase your credit score?
    Do you intend to upgrade your school grade?
    Do you want to hack your cheating spouse Email, whatsapp, Facebook, instagram or any social network?
    Do you need any information concerning any database.
    Do you need to retrieve deleted files?
    Do you need to clear your criminal records or DMV?
    Do you want to remove any site or link from any blog?
    you should contact this hacker, he is reliable and good at the hack jobs..
    contact : cybergoldenhacker at gmail dot com

    ReplyDelete
  5. I was in so much debit and needed a way to clear it up because my life was in danger, then I saw comments about cloned ATM Credit Cards that can be programmed to hack into and withdraw money from any ATM machines around you . I doubted this but decided to give it a try by contacting {skylinktechnes@yahoo.com} they responded with their guidelines on how the card works. I was assured that the card can withdraw $5,000 instant per day and it had a usage limit of 12 months. So I requested one & paid the delivery fee to obtain the card, i was shocked to see the parcel{card} delivered at my doorstep. I picked it up and went back inside and confirmed the workings and genuinity of the card at the atm machine closest to me. This is no doubt because I have the card & have made use of the card countless times without any complaints. These hackers are USA based hackers set out to help people with financial freedom!! Contact these email if you wants to get rich with this Via email skylinktechnes@yahoo.com whatsapp/t: +1(213)785-1553

    ReplyDelete

Post a Comment

Popular Posts