Secure Coding & OWASP Top 10 for Backend · レッスン

バックエンドにおけるクロスサイトスクリプティング(XSS)

バックエンドの脆弱性に起因するXSSの仕組みと、適切な出力エンコーディングおよびバリデーションの戦略を学びます。

レッスン 3/411 ステップ

「バックエンドにおけるクロスサイトスクリプティング(XSS)」はCoddyKit上の無料Secure Coding & OWASP Top 10 for Backendレッスンです。 これはレッスン3/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSecure Coding & OWASP Top 10 for Backend学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 Secure Coding & OWASP Top 10 for Backendコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

XSS from a Backend Perspective

Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.

While XSS attacks execute in the user's browser (client-side), the root cause often lies in how the backend application handles, stores, and outputs user-supplied data.

Backend's Role in XSS

Your backend application is responsible for managing user data. This includes:

  • Receiving input from users.
  • Storing that input (e.g., in a database).
  • Retrieving and sending that input back to browsers for display.

If the backend fails to properly process or 'sanitize' this data before sending it to the browser, it creates an XSS vulnerability.

Reflected XSS via Backend

Reflected XSS occurs when a backend application immediately returns user input in its response without proper encoding, and a browser then renders it.

Think of a search page where your search term is echoed back in the results. If the search term contains malicious script, and the backend doesn't handle it, the script runs.

Stored XSS via Backend

Stored XSS is often more severe. Here, malicious user input is:

  • Received by the backend.
  • Persisted (e.g., saved in a database, file system).
  • Later retrieved and displayed to other users or even administrators.

Examples include vulnerable comment sections, forum posts, or user profile fields where data is saved and then rendered without proper protection.

Vulnerable Backend Output

Consider this simplified Java example. It takes user input and directly embeds it into the HTML response. Try running it with some malicious input!

public class VulnerableOutput {
  public static void main(String[] args) {
    // Imagine this is user input from a web request
    String userInput = "<script>alert('XSS Attack!');</script>"; 
    
    System.out.println("<html><body>");
    System.out.println("<h1>Welcome, " + userInput + "!</h1>"); // Direct output
    System.out.println("</body></html>");
  }
}

The Problem: Code Execution

When the backend directly outputs user input like in the previous example, the browser interprets it as part of the HTML structure.

If the userInput contained <script>alert('XSS Attack!');</script>, the browser would execute the JavaScript code within the script tags.

This allows attackers to:

  • Steal cookies (session hijacking).
  • Deface websites.
  • Redirect users to malicious sites.
  • Execute arbitrary actions on behalf of the user.

Defending with Output Encoding

The primary defense against XSS, especially for data originating from the backend, is output encoding.

Output encoding converts special characters (like <, >, &, ", ') into their safe HTML entity equivalents (e.g., &lt;, &gt;).

This ensures the browser treats the input as plain text, not executable code.

Secure Backend with Encoding

Here's how you can implement a basic HTML encoding function in Java to prevent XSS. Many web frameworks provide built-in, more robust encoding utilities.

public class SecureOutput {
  // A simplified HTML encoder
  public static String htmlEncode(String input) {
    if (input == null) return "";
    return input
      .replace("&", "&amp;")
      .replace("<", "&lt;")
      .replace(">", "&gt;")
      .replace("\"", "&quot;")
      .replace("'", "&#x27;")
      .replace("/", "&#x2F;");
  }

  public static void main(String[] args) {
    String userInput = "<script>alert('XSS Attack!');</script>"; // Malicious input
    String encodedInput = htmlEncode(userInput); // Apply encoding!

    System.out.println("<html><body>");
    System.out.println("<h1>Welcome, " + encodedInput + "!</h1>"); // Safe output
    System.out.println("</body></html>");
  }
}

Input Validation vs. Encoding

It's important to distinguish between:

  • Input Validation: Checks if data is valid and safe *before* processing or storing (e.g., ensuring an email is in correct format, limiting length). This helps with overall data integrity and other attack types.
  • Output Encoding: Makes data safe for display *after* retrieval from the backend. This is the direct and crucial defense against XSS.

Both are vital for a secure application, but output encoding is your final safeguard against XSS when rendering user-controlled content.

XSS Defense Check

A social media platform's backend stores user posts in a database. When another user views a post, the backend retrieves and displays it. Which is the most effective measure to prevent XSS?

Recap: Guarding Against XSS

In this lesson, we learned that:

  • XSS vulnerabilities often originate from backend applications that improperly handle user-supplied data.
  • Both Reflected and Stored XSS rely on the backend sending unencoded malicious input to the browser.
  • The most critical defense is output encoding, which converts special characters into safe HTML entities before any user-controlled data is rendered.
  • Combining robust input validation with consistent output encoding provides the best protection against XSS.
無料で開始

AI チューターと学ぶ Secure Coding & OWASP Top 10 for Backend — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
12
レッスン
48

よくある質問

「バックエンドにおけるクロスサイトスクリプティング(XSS)」レッスンは無料ですか?

はい。「バックエンドにおけるクロスサイトスクリプティング(XSS)」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、Secure Coding & OWASP Top 10 for Backendコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 Secure Coding & OWASP Top 10 for Backendコースには全4レッスンが含まれています。

「バックエンドにおけるクロスサイトスクリプティング(XSS)」で何を学びますか?

バックエンドの脆弱性に起因するXSSの仕組みと、適切な出力エンコーディングおよびバリデーションの戦略を学びます。 ブラウザで直接実行するハンズオンコードでSecure Coding & OWASP Top 10 for Backendを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

Secure Coding & OWASP Top 10 for Backendを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのSecure Coding & OWASP Top 10 for Backendは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン3/4です。

「バックエンドにおけるクロスサイトスクリプティング(XSS)」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このSecure Coding & OWASP Top 10 for Backendレッスンでコードを書いて実行できますか?

はい。すべてのSecure Coding & OWASP Top 10 for Backendレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. SQLインジェクションの防止
  2. コマンドインジェクションとコードインジェクション
  3. バックエンドにおけるクロスサイトスクリプティング(XSS)
  4. XMLインジェクションとLDAPインジェクションの防止
← Secure Coding & OWASP Top 10 for Backendに戻る