Web Hack List

Later archive addition

Secure Content Sniffing for Web Browsers, or How to Stop Papers from Reviewing Themselves

Browsers' content sniffing can treat uploaded non-HTML files as HTML, so a crafted paper uploaded to a conference system can script the site and submit its own reviews. The authors built high-fidelity models of four browsers' sniffing algorithms and compared them with site filtering policies to derive attacks, then proposed a principled algorithm adopted by IE8, Chrome and HTML5.

Record

Researcher
Adam Barth, Juan Caballero and Dawn Song

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Barth, Juan Caballero and Dawn Song, first published at the original source. Preserved copies are kept so the citation survives its host.