Web Hack List

Collected research

The Unexpected Dangers of Dynamic JavaScript

Scripts generated per user session can be pulled in cross origin because script tags escape the same origin policy, so an attacker page can recover the data through global variables, overwritten global functions or tampered prototypes. A study of 150 top sites found 49 leaking login state, and others leaking emails, session tokens and CSRF secrets up to full account takeover.

Record

Researcher
Sebastian Lekies, Ben Stock, Martin Wentzel and Martin Johns
Published by
usenix.org
Format
Whitepaper
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sebastian Lekies, Ben Stock, Martin Wentzel and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .