Top 10 winner
Mario Heiderich -- Mutation XSS
The inner HTML Apocalypse : How MXSS attacks change everything we believed to know so far
Reading innerHTML makes browsers rewrite markup, so a string that passes every server- and client-side XSS filter can be mutated into a live vector. Seven mutations are named - backticks as attribute delimiters, XML namespaces on unknown elements, CSS escapes, entity handling in XML modes - and broke Yahoo! Mail, Roundcube, HTML Purifier and Caja. An 820-byte XMLSerializer shim blocks them.
Record
- Document
- The inner HTML Apocalypse : How MXSS attacks change everything we believed to know so far
- Researcher
- Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius and Edward Z. Yang
- Published by
- ACM
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius and Edward Z. Yang, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .