Web Hack List

Collected research

Preventing Capability Leaks in Secure JavaScript Subsets

WebBlaze - Preventing Capability leaks in Secure JavaScript Subsets

Project page for the NDSS 2010 paper on capability leaks in statically verified JavaScript subsets. Blacklist-based sandboxes such as ADsafe still let an advertisement reach methods the hosting page adds to built-in prototypes; a third of the Alexa US Top 100 would be exploitable. The fix is a whitelist of known-safe properties via namespaces, released as Blancura.

Record

Document
WebBlaze - Preventing Capability leaks in Secure JavaScript Subsets
Researcher
Matthew Finifter, Joel Weinberger and Adam Barth
Published by
webblaze.cs.berkeley.edu
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Finifter, Joel Weinberger and Adam Barth, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .