Collected research
New Methods in Automated XSS Detection: Dynamic XSS Testing Without Using Static Payloads
New Methods in Automated XSS Detection - Ken Belva - AppSecUSA 2015
A scanner method that stops firing static payloads and instead injects a unique slug, parses where it lands in the HTML, JavaScript or DOM, and builds a table of which characters survive the application's filters and transformations. From that context and character table it composes a dynamic exploit per injection point, finding stored and hard-to-reach XSS with fewer false positives.
Record
- Document
- New Methods in Automated XSS Detection - Ken Belva - AppSecUSA 2015
- Researcher
- Kenneth F. Belva
- Published by
- exploit-db.com
- Date
- Format
- Recording
- Topic
- XSS
In the archive
Related sources
- 38468 new methods in automated xss detection Whitepaper
- Mostafa Siraj's schedule for AppSecUSA 2015
- New Methods in Automated XSS Detection - Ken Belva - AppSecUSA 2015
Tags
This page is the archive's own catalogue record. The research is the work of Kenneth F. Belva, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .