Collected research
Preventing Capability Leaks in Secure JavaScript Subsets
WebBlaze - Preventing Capability leaks in Secure JavaScript Subsets
Project page for the NDSS 2010 paper on capability leaks in statically verified JavaScript subsets. Blacklist-based sandboxes such as ADsafe still let an advertisement reach methods the hosting page adds to built-in prototypes; a third of the Alexa US Top 100 would be exploitable. The fix is a whitelist of known-safe properties via namespaces, released as Blancura.
Record
- Document
- WebBlaze - Preventing Capability leaks in Secure JavaScript Subsets
- Researcher
- Matthew Finifter, Joel Weinberger and Adam Barth
- Published by
- webblaze.cs.berkeley.edu
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Matthew Finifter, Joel Weinberger and Adam Barth, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .