Web Hack List

Collected research

Cross-Origin JavaScript Capability Leaks: Detection, Exploitation, and Defense

USENIX Security 2009 paper page for work by Barth, Weinberger and Song on cross-origin JavaScript capability leaks, where a reference to an object from another origin escapes and defeats the same-origin policy. The authors instrument WebKit to detect such leaks dynamically, exploit the ones found, and propose an access-control defence.

Record

Researcher
Adam Barth, Joel Weinberger and Dawn Song
Published by
usenix.org
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Barth, Joel Weinberger and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .