Web Hack List

Collected research

SoK: Exploring Current and Future Research Directions on XS-Leaks through an Extended Formal Model

Models XS-Leaks as state changes followed by observable state retrieval, classifying 38 attacks and examining defense gaps. Derives request-count oracles from HTTP connection limits and server rate limits, then studies deployed protections and introduces Leakbuster to guide configuration.

Record

Researcher
Tom Van Goethem, Gertjan Franken, Iskander Sanchez-Rola, David Dworken and Wouter Joosen
Published by
ACM
Format
Whitepaper
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Tom Van Goethem, Gertjan Franken, Iskander Sanchez-Rola, David Dworken and Wouter Joosen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .