Collected research
FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications
FLAX names client-side validation bugs: untrusted data reaching JavaScript sinks such as eval, innerHTML, document.cookie and XHR URLs without adequate checking. It lowers JavaScript to an intermediate form, JASIL, tracks taint at character level, extracts a small executable acceptor slice per sink and fuzzes it with sink-aware attack vectors. It found 11 unknown bugs in 40 real applications.
Record
- Researcher
- Prateek Saxena, Steve Hanna, Pongsin Poosankam and Dawn Song
- Published by
- ndss-symposium.org
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Prateek Saxena, Steve Hanna, Pongsin Poosankam and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .