Collected research
JavaScript Global Namespace Pollution
pdp sketches detecting JavaScript malware by diffing the global object before and after untrusted input, with a small recursive walker, and then the evasions: wrap the payload in a closure that touches neither window nor document, or hide it on prototypes and other synthetic-sugar objects. DOM mutation is noted as the blind spot nobody checks.
Record
- Researcher
- pdp
- Published by
- gnucitizen.org
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of pdp, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .