-
1
-
-
84874550218
-
-
United States
-
Alexa top sites United States, http://www.alexa.com
-
Alexa top sites
-
-
-
3
-
-
49949108558
-
-
The Web Application Security Consortium
-
The Web Application Security Consortium, http://www.webappsec.org/ projects/wafec
-
-
-
-
4
-
-
49949106274
-
Cheat Sheet
-
XSS Cross Site Scripting
-
XSS (Cross Site Scripting) Cheat Sheet. Esp: for filter evasion, http://ha.ckers.org/xss.html
-
Esp: For filter evasion
-
-
-
5
-
-
49949102288
-
-
Hackers broaden reach of cross-site scripting attacks. ComputerWeekly.com (March 2007)
-
Hackers broaden reach of cross-site scripting attacks. ComputerWeekly.com (March 2007)
-
-
-
-
8
-
-
49949109144
-
CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations
-
Bandhakavi, S., Bisht, P., Madhusudan, P., Venkatakrishnan, V.N.: CANDID: Preventing SQL Injection Attacks using Dynamic Candidate Evaluations. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 12-24 (2007)
-
(2007)
Proceedings of the 14th ACM Conference on Computer and Communications Security
, pp. 12-24
-
-
Bandhakavi, S.1
Bisht, P.2
Madhusudan, P.3
Venkatakrishnan, V.N.4
-
11
-
-
50249115131
-
Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications
-
Balzarotti, D., et al.: Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In: IEEE Symposium on Security and Privacy (2008)
-
(2008)
IEEE Symposium on Security and Privacy
-
-
Balzarotti, D.1
-
13
-
-
57349153984
-
-
Wassermann, G., et al.: Static Detection of Cross-Site Scripting Vulnerabilities. In: Proceedings of the 30th International Conference on Software Engineering (May 2008)
-
Wassermann, G., et al.: Static Detection of Cross-Site Scripting Vulnerabilities. In: Proceedings of the 30th International Conference on Software Engineering (May 2008)
-
-
-
-
14
-
-
33751027156
-
-
Jovanovic, N., et al.: Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In: IEEE Symposium, on Security and Privacy (May 2006)
-
Jovanovic, N., et al.: Pixy: A Static Analysis Tool for Detecting Web Application Vulnerabilities. In: IEEE Symposium, on Security and Privacy (May 2006)
-
-
-
-
15
-
-
49949103832
-
-
Vogt, P., et al: Cross-Site Scripting Prevention with Dynamic Data Tainting and Static Analysis. In: NDSS, San Diego (2007)
-
Vogt, P., et al: Cross-Site Scripting Prevention with Dynamic Data Tainting and Static Analysis. In: NDSS, San Diego (2007)
-
-
-
-
16
-
-
33745213901
-
Defending Against Injection Attacks through Context-Sensitive String Evaluation
-
Pietraszek, T., et al: Defending Against Injection Attacks through Context-Sensitive String Evaluation. In: Recent Advances in Intrusion Detection (2005)
-
(2005)
Recent Advances in Intrusion Detection
-
-
Pietraszek, T.1
-
17
-
-
41149097554
-
BEEP: Browser-Enforced Embedded Policies
-
Jim, T., et al.: BEEP: Browser-Enforced Embedded Policies. In: International WWW Conference (2007)
-
(2007)
International WWW Conference
-
-
Jim, T.1
-
21
-
-
49949119294
-
-
Samy. I'm popular (2005), http://namb.la/popular
-
(2005)
Samy. I'm popular
-
-
-
22
-
-
84910681237
-
Static Detection of Security Vulnerabilities in Scripting Languages
-
Xie, Y., Aiken, A.: Static Detection of Security Vulnerabilities in Scripting Languages. In: USENIX Security Symposium (2006)
-
(2006)
USENIX Security Symposium
-
-
Xie, Y.1
Aiken, A.2
-
23
-
-
85038810709
-
Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks
-
Xu, W., Bhatkar, S., Sekar, R.: Taint-Enhanced Policy Enforcement: A Practical Approach to Defeat a Wide Range of Attacks. In: USENIX Security Symposium (2006)
-
(2006)
USENIX Security Symposium
-
-
Xu, W.1
Bhatkar, S.2
Sekar, R.3
|