메뉴 건너뛰기




Volumn , Issue , 2010, Pages 91-99

Regular expressions considered harmful in client-side XSS filters

Author keywords

browser; cross site scripting; filter; web; XSS

Indexed keywords

BUFFER OVERFLOWS; BUG-FREE; CROSS SITE SCRIPTING; FILTER DESIGNS; HIGH PRECISION; OPEN SOURCES; REGULAR EXPRESSIONS; RENDERING ENGINE; SECURITY VULNERABILITIES;

EID: 77954612255     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/1772690.1772701     Document Type: Conference Paper
Times cited : (141)

References (24)
  • 4
    • 77954604693 scopus 로고    scopus 로고
    • Facebook. Fbjs. http://wiki.developers.facebook.com/index.php/FBJS.
    • Fbjs
  • 5
    • 0003889134 scopus 로고    scopus 로고
    • chapter 20.4 The Data-Tainting Security Model. O'Reilly & Associates, Inc., second edition, January
    • David Flanagan. JavaScript: The Definitive Guide, chapter 20.4 The Data-Tainting Security Model. O'Reilly & Associates, Inc., second edition, January 1997.
    • (1997) JavaScript: The Definitive Guide
    • Flanagan, D.1
  • 7
    • 84870849340 scopus 로고    scopus 로고
    • Google. V8 benchmark suite. http://v8.googlecode.com/svn/data/benchmarks/ v5/run.html.
    • V8 Benchmark Suite
  • 9
    • 77954611446 scopus 로고    scopus 로고
    • Apple Inc.
    • Apple Inc. Sunspider. http://www2.webkit.org/perf/sunspider-0.9/ sunspider.html.
    • Sunspider
  • 16
    • 77954587701 scopus 로고    scopus 로고
    • Microsoft. About dynamic properties. http://msdn.microsoft.com/en-us/ library/ms537634(VS.85).aspx.
    • About Dynamic Properties
  • 17
    • 77954576586 scopus 로고    scopus 로고
    • Mitre. CVE-2009-4074
    • Mitre. CVE-2009-4074.
  • 18
    • 85027442855 scopus 로고    scopus 로고
    • Our favorite XSS filters/IDS and how to attack them, 2009
    • Eduardo Vela Nava and David Lindsay. Our favorite XSS filters/IDS and how to attack them, 2009. Black Hat USA presentation.
    • Black Hat USA Presentation
    • Nava, E.V.1    Lindsay, D.2
  • 19
    • 77954611157 scopus 로고    scopus 로고
    • October
    • Jeremias Reith. Internals of noXSS, October 2008. http://www.noxss.org/ wiki/Internals.
    • (2008) Internals of NoXSS
    • Reith, J.1
  • 21
    • 77954611896 scopus 로고    scopus 로고
    • Februrary
    • Steve. Preventing frame busting and click jacking, Februrary 2009. http://coderrr.wordpress.com/2009/02/13/preventing-frame-busting-and-click- jacking-ui-redressing/.
    • (2009) Preventing Frame Busting and Click Jacking
    • Steve1
  • 24
    • 77954568973 scopus 로고    scopus 로고
    • Michal Zalewski. Browser Security Handbook, volume 2. http://code.google.com/p/browsersec/wiki/Part2#Arbitrary-page-mashups-(UI- redressing).
    • Browser Security Handbook , vol.2
    • Zalewski, M.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.