Web Hack List

Collected research

CSP Is Dead, Long Live CSP!

CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy

Internet-scale measurement of Content Security Policy across 1.6 million hosts and 26,011 distinct policies finds 94.72 percent of policies bypassable, chiefly because whitelisted script hosts serve endpoints that hand back attacker-controlled script. Proposes the strict-dynamic keyword so nonce-based policies can replace host whitelists.

Record

Document
CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy
Researcher
Lukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies and Artur Janc
Published by
research.google
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Lukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies and Artur Janc, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .