Other nomination
New Methods in Automated XSS Detection: Dynamic XSS Testing Without Using Static Payloads
A scanner method that stops firing static payloads and instead injects a unique slug, parses where it lands in the HTML, JavaScript or DOM, and builds a table of which characters survive the application's filters and transformations. From that context and character table it composes a dynamic exploit per injection point, finding stored and hard-to-reach XSS with fewer false positives.
Record
- Researcher
- Kenneth F. Belva
- Published by
- exploit-db.com
- Date
- Format
- Recording
In the archive
Related sources
- Slides
- Practical Timing Attacks using Mathematical Amplification of Time Difference in == Operator
- Talk recording
Tags
This page is the archive's own catalogue record. The research is the work of Kenneth F. Belva, first published at the original source. Preserved copies are kept so the citation survives its host.