Web Hack List

Collected research

Code-Injection Attacks in Browsers Supporting Policies (return-to-JavaScript)

A W2SP 2009 paper on XSS attacks that defeat browser-enforced policy frameworks. It examines BEEP, which whitelists trusted scripts in the browser, and shows attacks analogous to return-to-libc that reuse already-trusted client-side code rather than injecting new script. It proposes isolating trusted code via policies expressed as browser actions.

Record

Researcher
Elias Athanasopoulos, Vasilis Pappas and Evangelos P. Markatos
Published by
ieee-security.org
Format
Whitepaper
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Elias Athanasopoulos, Vasilis Pappas and Evangelos P. Markatos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .