Top 10 winner
Permanent backdooring of HTML5 client-side application
How a Platform Using HTML5 Can Affect the Security of Your Website
Caching application JavaScript in HTML5 localStorage turns any reflected XSS on the caching origin into a persistent, self-reloading compromise. The article documents a real case: the Apture widget cached 272KB of code and eval'd it, and a reflected XSS on cdn.apture.com let an attacker poison that cache. The payload then executed on every third-party site embedding Apture.
Record
- Document
- How a Platform Using HTML5 Can Affect the Security of Your Website
- Researcher
- Joey Tyson
- Published by
- Security Musings
- Date
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Joey Tyson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .