Collected research
Code-Injection Attacks in Browsers Supporting Policies (return-to-JavaScript)
A W2SP 2009 paper on XSS attacks that defeat browser-enforced policy frameworks. It examines BEEP, which whitelists trusted scripts in the browser, and shows attacks analogous to return-to-libc that reuse already-trusted client-side code rather than injecting new script. It proposes isolating trusted code via policies expressed as browser actions.
Record
- Researcher
- Elias Athanasopoulos, Vasilis Pappas and Evangelos P. Markatos
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Elias Athanasopoulos, Vasilis Pappas and Evangelos P. Markatos, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .