Web Hack List

Collected research

A Wolf in Sheep's Clothing: The Dangers of Persistent Web Browser Storage

A survey of persistent browser storage — HTTP cookies, Flash Local Shared Objects, Google Gears and HTML5 database storage — and the abuse each enables. It introduces client-side SQL injection (csSQLi): XSS on a site lets an attacker open and query the local SQLite database Gears or HTML5 keeps, demonstrated against Paymo.biz, plus persistent client-side XSS held in a site's own search history.

Record

Researcher
Michael Sutton
Published by
blackhat.com
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Michael Sutton, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .