Web Hack List

Later archive addition

Hand Sanitizers in the Wild: A Large-scale Study of Custom JavaScript Sanitizer Functions

Extracts custom JavaScript sanitizers from observed DOM XSS data flows, then applies symbolic string analysis to generate bypasses and validates them in browsers. SemAttack models sanitizer operations and HTML contexts, uncovering ineffective filters and sanitizer combinations across a large web crawl.

Record

Researcher
David Klein, Thomas Barber, Souphiane Bensalim, Ben Stock and Martin Johns
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Klein, Thomas Barber, Souphiane Bensalim, Ben Stock and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host.