Web Hack List

Collected research

Security Study of Service Worker Cross-Site Scripting

Finds service workers that trust configuration in their registration URL and pass it to script-loading or execution sinks. Attackers can obtain persistent worker-level code execution through page URL forwarding or existing JavaScript access. SW-Scanner combines instrumentation and replay to confirm 40 vulnerable sites.

Record

Researcher
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang and Guofei Gu
Published by
ACM
Format
Whitepaper
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang and Guofei Gu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .