• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Trusted Types API protection from DOM-based XSS

Trusted Types API protection from DOM-based XSS

17/02/2019 18:26 by giorgos

Trusted Types API: Google has created a new API that will help Chrome fight certain types of cross-site scripting (XSS) attacks, adding another level of browser-level protection.

This new feature is called Trusted Types and is a browser API Chrome which Google has been working on in recent months.code - Trusted Types API protection from DOM-based XSS

The company's developers plan to test the Trusted Types API throughout 2019, between Chrome 73 and Chrome 76, before enabling it as a permanent security feature for all Chrome users later in the year.

This new security feature was developed to protect users from one of three types of cross-site scripting vulnerabilities, DOM-based (or type-0) XSS.

A detailed analysis of the three XSS types available here, for readers who want to learn more about XSS.

DOM-based XSS is basically a vulnerability found in a site's source code. Hackers exploit so-called injection points to enter code into the browser's DOM (page source code) to perform unwanted malicious actions, such as stealing cookies, handling page content, redirecting users, etc.

The Trusted Types API will prevent such attacks by allowing page owners to lock known "injection points" into a site's code, which is often the root cause of DOM-based XSS.

Webmasters will be able to enable the imminent protection of Chrome Trusted Types by assigning a specific value to the Content Security Policy (CSP) HTTP response header.

Once enabled, access to the DOM injection points will be restricted by Chrome's built-in Trusted Types API, preventing any attacks before the XSS code utilizes the DOM page source code to attack users.

A tutorial on how website owners can enable the Trusted Types API through the Content Security Policy (CSP) HTTP response header and how users can configure Chrome to use early versions of the API is available at Google Developers blog.

  • Copyright in Europe: changes to March - April
Trusted Types API protection from DOM-based XSS was last modified: 17 February, 2019, 6: 26 pm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: based, cookies, cross-site, hackers, injection

You May Also Like

SolarWinds Hackers stole Microsoft source code
The technique of a MAC flooding attack
Microsoft: 1000 hackers in SolarWinds attack

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Microsoft Store Other malicious Windows 10 applications have been found in the Microsoft Store
Next Post: Kodi 18.1 Leia: new version. Just released »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.