Web Hack List

Collected research

Self-Exfiltration: The Dangers of Browser-Enforced Information Flow Control

A W2SP paper arguing that restricting outgoing data by destination is inherently unsound. An attacker who cannot send stolen data to their own domain can instead stash it in a whitelisted site's own database, then fetch it independently later. The authors name eight browser mechanisms defeated this way and found at least one such channel on every one of the Alexa top 100 sites.

Record

Researcher
Eric Y. Chen, Sergey Gorbaty, Astha Singhal and Collin Jackson
Published by
ieee-security.org
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Eric Y. Chen, Sergey Gorbaty, Astha Singhal and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .