Web Hack List

Collected research

JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals

Client-side CSRF is a forged request built by the page's own JavaScript from attacker-controlled inputs such as the URL, so it evades defences aimed at classic CSRF. JAW builds hybrid property graphs of JavaScript applications and runs declarative traversals over them, uncovering 12,701 forgeable requests across 87 applications and exploits against seven.

Record

Researcher
Soheil Khodayari and Giancarlo Pellegrino
Published by
usenix.org
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Soheil Khodayari and Giancarlo Pellegrino, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .