Collected research
Regular Expressions Considered Harmful in Client-Side XSS Filters
The authors show that IE8, NoScript and noXSS block reflected XSS by running regular expressions over the raw response, so they are either slow or evadable, and their mangling can disable a victim site's own security scripts. Their XSSAuditor instead sits between the HTML parser and the JavaScript engine, blocking scripts after parsing. It ships enabled in Chrome.
Record
- Researcher
- Daniel Bates, Adam Barth and Collin Jackson
- Published by
- adambarth.com
- Format
- Whitepaper
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Daniel Bates, Adam Barth and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .