Proceedings of the 15th ACM Asia Conference on Computer and Communications Security 2020
DOI: 10.1145/3320269.3372201
|View full text |Cite
|
Sign up to set email alerts
|

Assessing the Impact of Script Gadgets on CSP at Scale

Abstract: The Web, as one of the core technologies of modern society, has profoundly changed the way we interact with people and data. One of the worst attacks on the Web is Cross-Site Scripting (XSS), in which an attacker is able to inject their malicious JavaScript code into a Web application, giving this code full access to the

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1

Citation Types

0
2
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
6

Relationship

1
5

Authors

Journals

citations
Cited by 7 publications
(2 citation statements)
references
References 15 publications
0
2
0
Order By: Relevance
“…Recently, Lekies et al [29] discuss how script gadgets can be used to bypass existing cross-site scripting mitigation. Roth et al [40] further study the effect of script gadgets on content security policies. Steffens and Stock [46] present PMForce, a lightweight dynamic analysis augmented with forced execution for studying post message handlers.…”
Section: Nodejs Ecosystem Securitymentioning
confidence: 99%
“…Recently, Lekies et al [29] discuss how script gadgets can be used to bypass existing cross-site scripting mitigation. Roth et al [40] further study the effect of script gadgets on content security policies. Steffens and Stock [46] present PMForce, a lightweight dynamic analysis augmented with forced execution for studying post message handlers.…”
Section: Nodejs Ecosystem Securitymentioning
confidence: 99%
“…In addition to measuring CSP adoption and bypasses, Pan et al [26] proposed to automatically curate CSPs from observed scripts. Similarly, Roth et al [27] relied on automated CSP generation through observed scripts to assess the dangers of gadget-enabling libraries that are co-hosted with benign, required JavaScript. Eriksson and Sabelfeld [12] proposed Au-toNav, a tool capable of automatically curating navigate-to directives for CSP.…”
Section: Cspmentioning
confidence: 99%