Introduction
The XSS injection problem was discussed before in an XSS hole I left by accident; one situation analyzed there was reusing data transmitted from another page, and the uncontrollability of that data allowed a malicious person to tamper with the data for XSS injection.
How the Rank Page Is Implemented
But what does the rank page have to do with XSS injection?
Here, please note one thing: the ranking results on the rank page come from data in LeanCloud. This site is a static site created by hexo, and the statistics feature of course also relies on LeanCloud.
The main logic of this page is as follows:
1 | var Counter = AV.Object.extend('Counter'); |
Security Problems of Using the Return Values Directly
I don’t know whether everyone noticed: we expose LeanCloud‘s App ID and
App Key on the front-end page, so anyone can transmit any data.
In this situation, merely storing data is not a problem; the problem lies in reading. If the data read has already been tampered with and we then render it directly onto the page, XSS injection can very likely occur.
Solution — (Add a Filtering Layer)
If you go to the rank page and look at its code, you’ll find this section:
1 | // This map stores all known titles |
In the code above, an important idea is that data from LeanCloud cannot be trusted; the validity of this layer of data
must be verified once, to prevent malicious people from modifying the database.