Web Hack List

Collected research

The Remote on the Local: Exacerbating Web Attacks Via Service Workers Caches

Existing same-origin malicious JavaScript can rewrite service-worker caches to remove CSP and other security headers, reorder cached scripts, and persist attacks after server fixes. Cached authenticated responses can also remain readable after logout. The paper proposes restricting page access to worker caches.

Record

Researcher
Dolière Francis Somé, Stefano Calzavara, Marco Squarcina and Matteo Maffei
Published by
secweb.work
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dolière Francis Somé, Stefano Calzavara, Marco Squarcina and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .