15–25 min Updated

Reflected XSS

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

When building a website, you need to be sure you do not accidentally create a channel that allows malicious JavaScript to be bounced off your server.

Prevalence
Common
Exploitability
Easy
Impact
Harmful

What is reflected XSS?

Reflected XSS is a cross-site scripting (XSS) attack, a type of injection attack, in which malicious JavaScript in an HTTP request is echoed back in the response. The attacker puts the script in a link, usually a query parameter, and tricks a victim into clicking it. The script then runs in the victim's browser with the privileges of your site.

What you'll learn

  • How a script in a request gets echoed back and run in a victim's browser
  • Which pages are most likely to reflect user input
  • How escaping dynamic content and a Content Security Policy stop the attack

Where this lesson counts

OWASP Top 10

PCI DSS 4.0

  • Reflected XSS lab

    Mal notices that a restaurant review site echoes search terms back without escaping them. Watch him build a search URL containing a script, email it to Vic and collect Vic's session ID from his server log after the redirect.

  • How to prevent Reflected XSS

    The prevention guide covers three approaches:

    • Escape Dynamic Content
    • Allowlist Values
    • Implement a Content Security Policy
  • Reflected XSS quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.

  • DOM-based XSS

    If you make use of URI fragments in your site, you need to ensure they cannot be abused to inject malicious JavaScript.

  • Open Redirects

    Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.