Abusing browser address bar for fun and profit - an empirical investigation of add-on cross site scripting attacks

3Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Add-on JavaScript originating from users’ inputs to the browser brings new functionalities such as debugging and entertainment, however it also leads to a new type of cross-site scripting attack (defined as add-on XSS by us), which consists of two parts: a snippet of JavaScript in clear text, and a spamming sentence enticing benign users to input the previous JavaScript. In this paper, we focus on the most common add-on XSS, the one caused by browser address bar JavaScript. To measure the severity, we conduct three experiments: (i) analysis on real-world traces from two large social networks, (ii) a user study by means of recruiting Amazon Mechanical Turks [4], and (iii) a Facebook experiment with a fake account. We believe as the first systematic and scientific study, our paper can ring a bell for all the browser vendors and shed a light for future researchers to find an appropriate solution for add-on XSS.

Cite

CITATION STYLE

APA

Cao, Y., Yang, C., Rastogi, V., Chen, Y., & Gu, G. (2015). Abusing browser address bar for fun and profit - an empirical investigation of add-on cross site scripting attacks. In Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST (Vol. 152, pp. 582–601). Springer Verlag. https://doi.org/10.1007/978-3-319-23829-6_45

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free