What is cross-site scripting?
Cross-site scripting is called XSS. An attacker sneaks a small piece of code into your web page, for example through a comment box or a search form. When another visitor opens the page, the code runs in their browser. It can steal their login or send them to a fake page.
Think of someone who leaves a booby-trapped note on your notice board. Anyone who reads it gets tricked.
The bad code is usually JavaScript. It often looks like this:
<script>alert('hacked')</script>
What does a WAF do?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads every request to your website. If it sees script tags or other XSS tricks in a form or address, it blocks the request. The bad code never reaches your page.
Most WAFs use ModSecurity with a rule set. The OWASP Core Rule Set has a group of rules just for XSS.
Steps
- Turn on your WAF. In cPanel, look in Security for ModSecurity. In Plesk, use Web Application Firewall in Tools & Settings. In WHM, search
ModSecurity. Ask Hostvento support if you cannot find it. - Set the engine to On, not just detection.
- Make sure a good rule set is installed, such as OWASP.
- Check that the XSS rule group is switched on.
- Test with your own site, using the example below.
- Read the log to see the block was recorded.
Test safely
Type this into your own site's address bar, changing the domain:
https://example.com/?q=<script>alert(1)</script>
A WAF should answer with "403 Forbidden". Test only on your own sites.
Do more than the WAF
A WAF helps, but good site habits matter too.
- Keep your website software, themes and plugins updated.
- Remove plugins you do not use.
- Do not allow visitors to post raw HTML in comments.
- If you build sites, escape output. This means turning characters like < into safe text so the browser shows them instead of running them.
Need help? Open a support ticket.
Quick recap
- XSS sneaks bad code into pages that other visitors view.
- A WAF blocks requests that contain such code.
- Turn the engine On with a rule set like OWASP.
- Test on your own site and check the log.
- Keep your software updated.