HomeSecurityGoogle CSP Evaluator and CSP Mitigator anti XSS plugins

Google CSP Evaluator and CSP Mitigator anti XSS plugins

Google has released two new tools called CSP Evaluator and CSP Mitigator that help security researchers identify vulnerabilities that enable XSS attacks.

Both tools revolve around a security mechanism implemented by all major browsers, albeit in a somewhat different way.

What is CSP or Content Security Policy?

CSP is a set of rules that allow developers to restrict the scripts that are allowed to run within a page, so that when attackers manage to figure out a way to pass HTML code inside a vulnerable application, they are unable to load malicious scripts because the CSP policy strictly prohibits and blocks these payloads at the browser level.bad code Google

Despite the benefits of this security mechanism, Google reports that 95 percent of billions of domains scanned during a recent study have inappropriate CSP policies, allowing attackers to bypass CSP protection and launch XSS (cross-site scripting) attacks.

With the release of CSP Evaluator and CSP Mitigator, in the form of a standalone website scanner and Chrome extensions, Google hopes that webmasters will be able to test the CSP policies they use and improve their website's protection capabilities.

Try plugins (Chrome)

CSP Evaluator

CSP Mitigator

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS