15–25 min Updated

DOM-based XSS

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

If you make use of URI fragments in your site, you need to ensure they cannot be abused to inject malicious JavaScript.

Prevalence
Rare
Exploitability
Easy
Impact
Harmful

What is DOM-based XSS?

DOM-based XSS is a cross-site scripting (XSS) attack, a type of injection attack, that takes place entirely in the browser. Client-side JavaScript reads attacker-controlled data, often from the URI fragment, and writes it into the page without escaping, so the attacker's script runs. Because the payload may never be sent to the server, server-side defenses cannot detect it.

What you'll learn

  • What a URI fragment is and why the server never sees it
  • How client-side code that writes unescaped data into the page runs attacker scripts
  • How frameworks, code audits and a Content Security Policy prevent DOM-based XSS

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • DOM-based XSS lab

    A site with infinite scroll tracks your position in the URL fragment and writes it into the page without checking it. See how an attacker puts JavaScript in the fragment, and how it runs in the browser of anyone who follows the link.

  • How to prevent DOM-based XSS

    The prevention guide covers six approaches:

    • Use a JavaScript Framework
    • Audit Your Code Carefully
    • Parse JSON Carefully
    • Detect Unsafe Code Using Development Tools
    • Don't Use URI Fragments At All!
    • Implement a Content Security Policy
  • DOM-based XSS quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.

  • Reflected XSS

    When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.

  • Prototype Pollution

    If an attacker can access and modify prototype objects in JavaScript, you are in danger.

  • CSS Injection

    Attackers can manipulate user-generated CSS to extract sensitive data.