Web Hack List

Collected research

Regular Expressions Considered Harmful in Client-Side XSS Filters

The authors show that IE8, NoScript and noXSS block reflected XSS by running regular expressions over the raw response, so they are either slow or evadable, and their mangling can disable a victim site's own security scripts. Their XSSAuditor instead sits between the HTML parser and the JavaScript engine, blocking scripts after parsing. It ships enabled in Chrome.

Record

Researcher
Daniel Bates, Adam Barth and Collin Jackson
Published by
adambarth.com
Format
Whitepaper
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Bates, Adam Barth and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .