Collected research
JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals
Client-side CSRF is a forged request built by the page's own JavaScript from attacker-controlled inputs such as the URL, so it evades defences aimed at classic CSRF. JAW builds hybrid property graphs of JavaScript applications and runs declarative traversals over them, uncovering 12,701 forgeable requests across 87 applications and exploits against seven.
Record
- Researcher
- Soheil Khodayari and Giancarlo Pellegrino
- Published by
- usenix.org
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Soheil Khodayari and Giancarlo Pellegrino, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .