Web Hack List

Collected research

An Empirical Study of Privacy-Violating Information Flows in JavaScript Web Applications

A rewriting-based JavaScript information-flow engine was built inside Chrome, injecting and propagating taints in rewritten source rather than in the runtime, then run over the Alexa top 50,000. It confirmed 46 sites sniffing browser history, cookies leaking to ad networks, and 7 popular sites covertly tracking clicks and mouse movement. Overhead was about 3x on script execution.

Record

Researcher
Dongseok Jang, Ranjit Jhala, Sorin Lerner and Hovav Shacham
Published by
cs.cornell.edu
Format
Whitepaper
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dongseok Jang, Ranjit Jhala, Sorin Lerner and Hovav Shacham, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .