Web Hack List

Later archive addition

Regular Expressions Considered Harmful in Client-Side XSS Filters

The authors show that IE8, NoScript and noXSS block reflected XSS by running regular expressions over the raw response, so they are either slow or evadable, and their mangling can disable a victim site's own security scripts. Their XSSAuditor instead sits between the HTML parser and the JavaScript engine, blocking scripts after parsing. It ships enabled in Chrome.

Record

Researcher
Daniel Bates, Adam Barth and Collin Jackson
Format
Whitepaper

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Daniel Bates, Adam Barth and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host.