SSCP Systems Security Certified PractitionerSystems and Application SecurityEasy

A security analyst is reviewing a web application's design for potential vulnerabilities related to user input. The application allows users to submit HTML-formatted comments, which are then displayed to other users. The analyst is concerned about attacks where malicious scripts could be executed in other users' browsers. Which of the following mitigation techniques would be most effective against this specific type of attack?

  1. AUsing parameterized queries for all database interactions.
  2. BSanitizing or encoding all user-supplied HTML content before display.
  3. CImplementing server-side input validation to check for SQL injection patterns.
  4. DConfiguring a Web Application Firewall (WAF) to block common attack signatures.
Show answer & explanation

Correct answer: B. Sanitizing or encoding all user-supplied HTML content before display.

Sanitizing or encoding user-supplied HTML content converts potentially malicious scripts into harmless text, preventing them from being executed in the browser, which is the core defense against XSS.

Why the other options are wrong

  • A. Parameterized queries protect against SQL injection by separating code from data, which is unrelated to XSS.
  • C. Server-side input validation for SQL injection patterns addresses database attacks, not client-side script execution.
  • D. While a WAF can help, it's a perimeter defense; proper application-level sanitization is a more direct and robust mitigation for XSS.

Cross-Site Scripting (XSS) Prevention

Techniques used to prevent attackers from injecting malicious client-side scripts into web pages viewed by other users, typically by validating, sanitizing, or encoding user input.

  • Primarily targets client-side browsers.
  • Defenses include input validation, output encoding, and content security policies.
  • Can lead to session hijacking, defacement, or malware distribution.

Memory trick: Input must be clean, or scripts will run unseen.

More Systems and Application Security questions