Web Hack List

Collected research

FlashOver: Automated Discovery of Cross-site Scripting Vulnerabilities in Rich Internet Applications

FlashOver decompiles SWF files, regex-matches ActionScript variables reaching sinks like getURL and loadMovie, then builds attack URLs from ten injection templates and clicks 10,000 random points in a real Firefox to confirm execution. Run over 14,897 SWFs from the Alexa top 1,000, it found 286 exploitable files across 64 domains, six in the top 50, with no false positives.

Record

Researcher
Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Wouter Joosen and Frank Piessens
Published by
securitee.org
Format
Whitepaper
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Steven Van Acker, Nick Nikiforakis, Lieven Desmet, Wouter Joosen and Frank Piessens, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .