Collected research
The Unexpected Dangers of Dynamic JavaScript
Scripts generated per user session can be pulled in cross origin because script tags escape the same origin policy, so an attacker page can recover the data through global variables, overwritten global functions or tampered prototypes. A study of 150 top sites found 49 leaking login state, and others leaking emails, session tokens and CSRF secrets up to full account takeover.
Record
- Researcher
- Sebastian Lekies, Ben Stock, Martin Wentzel and Martin Johns
- Published by
- usenix.org
- Format
- Whitepaper
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sebastian Lekies, Ben Stock, Martin Wentzel and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .