Talking about My Generation: Targeted DOM-based XSS Exploit Generation using Dynamic Data Flow Analysis

26Citations
Citations of this article
17Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Since the invention of JavaScript 25 years ago, website functionality has been continuously shifting from the server-side to the client-side. Web browsers have evolved into an application platform, and HTML5 emerged as a first-class environment for building rich cross-platform applications. This additional functionality on the client-side comes with the added risk of new security issues with increasingly severe consequences. In this work, we investigate the prevalence of DOM-based Cross-Site Scripting (DOM-based XSS) in the top 100, 000 most popular websites using a novel targeted exploit generation technique based on dynamic data-flow tracking. In total, this work finds 15, 710 potentially insecure dataflows where information from the URL is injected into the HTML of the Web page. Using large-scale exploit generation and validation services, 7199 of these flows lead to JavaScript execution, across 711 different domains. This represents a successful exploit rate of 45.82%, improving on previous methods by factors of 1.8 and 1.9 respectively.

Cite

CITATION STYLE

APA

Bensalim, S., Klein, D., Barber, T., & Johns, M. (2021). Talking about My Generation: Targeted DOM-based XSS Exploit Generation using Dynamic Data Flow Analysis. In EuroSec 2021 - Proceedings of the 14th European Workshop on Systems (pp. 27–33). Association for Computing Machinery, Inc. https://doi.org/10.1145/3447852.3458718

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free