Web Hack List

Collected research

Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials

Generates 12 million mutation-prone HTML fragments, sanitizes each with 11 server-side sanitizers, then renders the output in three browsers in both document and fragment mode, comparing parse trees by a bag-of-XPaths score. Text-content tags such as iframe and noscript, SVG/MathML namespace switches, CDATA and the --!> comment close are mishandled everywhere; with unencoded text nodes they bypass 9 of 11, and 19,843 payloads only turned dangerous after sanitizing.

Record

Researcher
David Klein and Martin Johns
Published by
ias.cs.tu-bs.de
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Klein and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .