Web Hack List

Collected research

New Methods in Automated XSS Detection: Dynamic XSS Testing Without Using Static Payloads

New Methods in Automated XSS Detection - Ken Belva - AppSecUSA 2015

A scanner method that stops firing static payloads and instead injects a unique slug, parses where it lands in the HTML, JavaScript or DOM, and builds a table of which characters survive the application's filters and transformations. From that context and character table it composes a dynamic exploit per injection point, finding stored and hard-to-reach XSS with fewer false positives.

Record

Document
New Methods in Automated XSS Detection - Ken Belva - AppSecUSA 2015
Researcher
Kenneth F. Belva
Published by
exploit-db.com
Date
Format
Recording
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Kenneth F. Belva, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .