Web Hack List

Collected research

In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the Web

Combines taint tracking and static analysis to find DOM reads that influence script execution, requests, links, and other sensitive operations. Pairs verified gadgets with markup injection points and studies parser behavior that can make later injected elements win selectors. Confirms 657 paired flows across 37 sites.

Record

Researcher
Jan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein, Thomas Barber, Martin Johns and Giancarlo Pellegrino
Published by
ACM
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein, Thomas Barber, Martin Johns and Giancarlo Pellegrino, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .