Web Hack List

Collected research

FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications

FLAX names client-side validation bugs: untrusted data reaching JavaScript sinks such as eval, innerHTML, document.cookie and XHR URLs without adequate checking. It lowers JavaScript to an intermediate form, JASIL, tracks taint at character level, extracts a small executable acceptor slice per sink and fuzzes it with sink-aware attack vectors. It found 11 unknown bugs in 40 real applications.

Record

Researcher
Prateek Saxena, Steve Hanna, Pongsin Poosankam and Dawn Song
Published by
ndss-symposium.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Prateek Saxena, Steve Hanna, Pongsin Poosankam and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .