Collected research
Spider-Scents: Grey-box Database-aware Web Scanning for Stored XSS
Approaches stored XSS detection from the storage side: rather than driving payloads through an application's input paths, Spider-Scents writes marker values directly into the database and maps them to the pages that render them, exposing outputs that lack escaping. Across 12 applications it reached 79-100% database coverage against 2-60% for three black-box scanners, and found 85 stored XSS vulnerabilities where the union of those tools found 32.
Record
- Researcher
- Eric Olsson, Benjamin Eriksson, Adam Doupé and Andrei Sabelfeld
- Published by
- usenix.org
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Eric Olsson, Benjamin Eriksson, Adam Doupé and Andrei Sabelfeld, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .