Collected research
Attacks on JavaScript Mashup Communication
Analyses four design choices in JavaScript mashup communication: lexical vs dynamic authorization, interfaces vs asymmetry, typed vs untyped, and values vs objects. Proof-of-concept escalations abuse caller, arguments, __proto__ and valueOf to compromise Safari's Web Inspector and gadget interfaces. Proposes PostMash, a postMessage stub-library design, shown on Google Maps at 60% slowdown.
Record
- Researcher
- Adam Barth, Collin Jackson and William Li
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Barth, Collin Jackson and William Li, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .