메뉴 건너뛰기




Volumn , Issue , 2011, Pages 587-600

Context-sensitive auto-sanitization in web templating languages using type qualifiers

Author keywords

Cross site scripting; Type systems

Indexed keywords

CONTEXT-SENSITIVE; CROSS SITE SCRIPTING; DEFENSE TECHNIQUES; EMERGING APPLICATIONS; FORMAL SECURITY; LEGACY APPLICATIONS; OPEN-SOURCE; OTHER APPLICATIONS; TEMPLATING; TYPE QUALIFIERS; TYPE SYSTEMS; WEB APPLICATION;

EID: 80755169453     PISSN: 15437221     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1145/2046707.2046775     Document Type: Conference Paper
Times cited : (74)

References (54)
  • 6
    • 74249123619 scopus 로고    scopus 로고
    • XCS: Cross channel scripting and its impact on web applications
    • H. Bojinov, E. Bursztein, and D. Boneh. XCS: Cross channel scripting and its impact on web applications. In CCS, 2009.
    • (2009) CCS
    • Bojinov, H.1    Bursztein, E.2    Boneh, D.3
  • 9
    • 80755127556 scopus 로고    scopus 로고
    • How I met your girlfriend
    • How I met your girlfriend, DEFCON'10. ohack.us/xss/2010-defcon.ppt.
    • DEFCON'10
  • 11
    • 80053084105 scopus 로고    scopus 로고
    • ClearSilver: Template Filters. http://www.clearsilver.net/docs/man- filters.hdf.
    • Template Filters
  • 12
    • 80755127551 scopus 로고    scopus 로고
    • CodeIgniter/system/libraries/Security.php
    • CodeIgniter/system/libraries/Security.php. https://bitbucket.org/ ellislab/codeigniter/src/8af0fb079f90/system/libraries/Security.php.
  • 15
    • 80755172922 scopus 로고    scopus 로고
    • Google autoescape implementation for gwt (java code). http://code.google.com/p/google-web-toolkit/source/browse/tools/lib/ streamhtmlparser/streamhtmlparser-jsilver-r10/streamhtmlparser-jsilver-r10-1.5. jar.
    • Google Autoescape Implementation for Gwt (java Code)
  • 19
    • 84928407537 scopus 로고    scopus 로고
    • Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks
    • M. V. Gundy and H. Chen. Noncespaces: using randomization to enforce information flow tracking and thwart cross-site scripting attacks. 16th Annual Network & Distributed System Security Symposium, 2009.
    • (2009) 16th Annual Network & Distributed System Security Symposium
    • Gundy, M.V.1    Chen, H.2
  • 25
    • 80053065711 scopus 로고    scopus 로고
    • JiftyManual. http://jifty.org/view/JiftyManual.
    • JiftyManual
  • 27
    • 33751027156 scopus 로고    scopus 로고
    • Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
    • N. Jovanovic, C. Krügel, and E. Kirda. Pixy: A static analysis tool for detecting web application vulnerabilities (short paper). In IEEE Symposium on Security and Privacy, 2006.
    • (2006) IEEE Symposium on Security and Privacy
    • Jovanovic, N.1    Krügel, C.2    Kirda, E.3
  • 32
    • 35348845024 scopus 로고    scopus 로고
    • SecuriFly: Runtime protection and recovery from web application vulnerabilities
    • Sept.
    • B. Livshits, M. Martin, and M. S. Lam. SecuriFly: Runtime protection and recovery from Web application vulnerabilities. Technical report, Stanford University, Sept. 2006.
    • (2006) Technical Report, Stanford University
    • Livshits, B.1    Martin, M.2    Lam, M.S.3
  • 33
    • 85084163766 scopus 로고    scopus 로고
    • Automatic generation of XSS and SQL injection attacks with goal-directed model checking
    • M. Martin and M. S. Lam. Automatic generation of XSS and SQL injection attacks with goal-directed model checking. In 17th USENIX Security Symposium, 2008.
    • (2008) 17th USENIX Security Symposium
    • Martin, M.1    Lam, M.S.2
  • 34
    • 80755159889 scopus 로고    scopus 로고
    • The Mason Book: Escaping Substitutions. http://www.masonbook.com/book/ chapter-2.mhtml.
    • Escaping Substitutions
  • 35
    • 77955186827 scopus 로고    scopus 로고
    • ConScript: Specifying and enforcing fine-grained security policies for JavaScript in the browser
    • May
    • L. Meyerovich and B. Livshits. ConScript: Specifying and enforcing fine-grained security policies for JavaScript in the browser. In IEEE Symposium on Security and Privacy, May 2010.
    • (2010) IEEE Symposium on Security and Privacy
    • Meyerovich, L.1    Livshits, B.2
  • 36
    • 78650896178 scopus 로고    scopus 로고
    • Document structure integrity: A robust basis for cross-site scripting defense
    • Y. Nadji, P. Saxena, and D. Song. Document structure integrity: A robust basis for cross-site scripting defense. In NDSS, 2009.
    • (2009) NDSS
    • Nadji, Y.1    Saxena, P.2    Song, D.3
  • 38
    • 80053075919 scopus 로고    scopus 로고
    • XSS Prevention Cheat Sheet. http://www.owasp.org/index.php/XSS-(Cross- Site-Scripting)-Prevention-Cheat-Sheet.
    • XSS Prevention Cheat Sheet
  • 39
    • 80053079139 scopus 로고    scopus 로고
    • Static enforcement of web application integrity through strong typing
    • Montreal, Canada, August
    • W. Robertson and G. Vigna. Static Enforcement of Web Application Integrity Through Strong Typing. In Proceedings of the USENIX Security Symposium, Montreal, Canada, August 2009.
    • (2009) Proceedings of the USENIX Security Symposium
    • Robertson, W.1    Vigna, G.2
  • 40
    • 80755172920 scopus 로고    scopus 로고
    • Ruby on Rails Security Guide. http://guides.rubyonrails.org/security. html.
    • Security Guide
  • 44
    • 80755159885 scopus 로고    scopus 로고
    • Smarty Template Engine: escape. http://www.smarty.net/manual/en/language. modifier.escape.php.
    • Escape
  • 45
    • 85029460807 scopus 로고    scopus 로고
    • Google Closure Templates. http://code.google.com/closure/templates/.
    • Closure Templates
  • 48
    • 80755173822 scopus 로고    scopus 로고
    • Template: Manual: Filters. http://template-toolkit.org/docs/manual/ Filters.html.
    • Manual: Filters
  • 52
    • 85038810709 scopus 로고    scopus 로고
    • Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks
    • W. Xu, S. Bhatkar, and R. Sekar. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. USENIX Security Symposium, 2006.
    • (2006) USENIX Security Symposium
    • Xu, W.1    Bhatkar, S.2    Sekar, R.3
  • 53
    • 80755127548 scopus 로고    scopus 로고
    • Yii Framework: Security. http://www.yiiframework.com/doc/guide/1.1/en/ topics.security.
    • Security
  • 54
    • 80755173830 scopus 로고    scopus 로고
    • Zend Framework: Zend Filter. http://framework.zend.com/manual/en/zend. filter.set.html.
    • Zend Filter


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.