Web Hack List

Top 10 winner

Mario Heiderich -- Mutation XSS

The inner HTML Apocalypse : How MXSS attacks change everything we believed to know so far

Reading innerHTML makes browsers rewrite markup, so a string that passes every server- and client-side XSS filter can be mutated into a live vector. Seven mutations are named - backticks as attribute delimiters, XML namespaces on unknown elements, CSS escapes, entity handling in XML modes - and broke Yahoo! Mail, Roundcube, HTML Purifier and Caja. An 820-byte XMLSerializer shim blocks them.

Record

Document
The inner HTML Apocalypse : How MXSS attacks change everything we believed to know so far
Researcher
Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius and Edward Z. Yang
Published by
ACM
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius and Edward Z. Yang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .