Preventing Cross-Site Scripting (XSS)

Cross-Site Scripting, or XSS, is a type of attack used by hackers to control the content of your web pages. Hackers insert a piece of code into your site, usually through an input field such as a search box, user ID, or Name/Address box. If your website is vulnerable to this type of attack, the hacker can control the content of your page, including the user's cookies or session variables.

Hackers use this type of attack to trick your visitors into providing personal data. Since visitors believe they are providing this information to your site, they are likely to provide sensitive information to hackers, since they trust your business. Hackers use information collected, such as usernames, passwords, credit card information, etc. to carry out identity theft and other criminal activities.

SiteLock's patent-pending 360-degree scan technology tests each input box on your website to ensure that they are not vulnerable to this type of attack. We verify the security of each input box on your website by inserting code in the way hackers would. Instead of taking over your page, though, we simply use harmless test procedures.

What measures can I put in place?

Make sure any applications you use are kept up-to-date and limit the use of third-party plug-in's where possible as they can be a source of many issues and may be updated less frequently or created by unscrupulous publishers. Use a website scanning service features XSS scripting scans, such as SiteLock Premium or SMB. If you are writing your own code, be sure to validate your input fields for special characters and ensure that the settings for your code are frequently updated and hardened for security. You can also take advantage of SiteLock's Expert Services team to correct any issues we identify in our scans.

  • payment
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

How to order SiteLock

You may click here to place an order for SiteLock for your site.  

What is SiteLock?

SiteLock is a simple and effective cloud-based security solution built specially for online...

What is the SiteLock Trust Seal?

The Trust Seal is a badge which you can display on your website to ensure customers feel safe...

What To Do When SiteLock Finds a Vulnerability

If SiteLock Shows a Failed Scan:If SiteLock finds a vulnerability, your dashboard will show a...

Virus Scanning (Drive-by Downloads)

If your site has been compromised by hackers, they may be using your website to distribute...