Web Hack List

Collected research

Hand Sanitizers in the Wild: A Large-scale Study of Custom JavaScript Sanitizer Functions

Extracts custom JavaScript sanitizers from observed DOM XSS data flows, then applies symbolic string analysis to generate bypasses and validates them in browsers. SemAttack models sanitizer operations and HTML contexts, uncovering ineffective filters and sanitizer combinations across a large web crawl.

Record

Researcher
David Klein, Thomas Barber, Souphiane Bensalim, Ben Stock and Martin Johns
Published by
swag.cispa.saarland
Format
Whitepaper
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Klein, Thomas Barber, Souphiane Bensalim, Ben Stock and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .