Web Hack List

Collected research

CTA: The weaknesses in client side xss filtering targeting Chrome's XSS Auditor

Black Hat USA 2014

Capture of the full Black Hat USA 2014 Briefings programme; the cited talk within it, Call To Arms, reports 17 flaws in Chrome's XSS Auditor that let an attacker rewrite an injection so the client-side filter passes it through. The authors automate bypass generation and measure it against thousands of real DOM-based XSS bugs.

Record

Document
Black Hat USA 2014
Published by
blackhat.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of blackhat.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .