Web Hack List

Later archive addition

Preventing Capability Leaks in Secure JavaScript Subsets

Project page for the NDSS 2010 paper on capability leaks in statically verified JavaScript subsets. Blacklist-based sandboxes such as ADsafe still let an advertisement reach methods the hosting page adds to built-in prototypes; a third of the Alexa US Top 100 would be exploitable. The fix is a whitelist of known-safe properties via namespaces, released as Blancura.

Record

Researcher
Matthew Finifter, Joel Weinberger and Adam Barth

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Finifter, Joel Weinberger and Adam Barth, first published at the original source. Preserved copies are kept so the citation survives its host.