-
1
-
-
50249115131
-
Saner: Composing static and dynamic analysis to validate sanitization in web applications
-
Oakland, CA, May
-
D. Balzarotti, M. Cova, V. Felmetsger, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications. In Proceedings of the IEEE Symposium on Security and Privacy, Oakland, CA, May 2008.
-
(2008)
Proceedings of the IEEE Symposium on Security and Privacy
-
-
Balzarotti, D.1
Cova, M.2
Felmetsger, V.3
Jovanovic, N.4
Kirda, E.5
Kruegel, C.6
Vigna, G.7
-
6
-
-
74249123619
-
XCS: Cross channel scripting and its impact on web applications
-
H. Bojinov, E. Bursztein, and D. Boneh. XCS: Cross channel scripting and its impact on web applications. In CCS, 2009.
-
(2009)
CCS
-
-
Bojinov, H.1
Bursztein, E.2
Boneh, D.3
-
9
-
-
80755127556
-
-
How I met your girlfriend
-
How I met your girlfriend, DEFCON'10. ohack.us/xss/2010-defcon.ppt.
-
DEFCON'10
-
-
-
11
-
-
80053084105
-
-
ClearSilver: Template Filters. http://www.clearsilver.net/docs/man- filters.hdf.
-
Template Filters
-
-
-
12
-
-
80755127551
-
-
CodeIgniter/system/libraries/Security.php
-
CodeIgniter/system/libraries/Security.php. https://bitbucket.org/ ellislab/codeigniter/src/8af0fb079f90/system/libraries/Security.php.
-
-
-
-
15
-
-
80755172922
-
-
Google autoescape implementation for gwt (java code). http://code.google.com/p/google-web-toolkit/source/browse/tools/lib/ streamhtmlparser/streamhtmlparser-jsilver-r10/streamhtmlparser-jsilver-r10-1.5. jar.
-
Google Autoescape Implementation for Gwt (java Code)
-
-
-
19
-
-
84928407537
-
Noncespaces: Using randomization to enforce information flow tracking and thwart cross-site scripting attacks
-
M. V. Gundy and H. Chen. Noncespaces: using randomization to enforce information flow tracking and thwart cross-site scripting attacks. 16th Annual Network & Distributed System Security Symposium, 2009.
-
(2009)
16th Annual Network & Distributed System Security Symposium
-
-
Gundy, M.V.1
Chen, H.2
-
22
-
-
84970882954
-
Fast and precise sanitizer analysis with BEK
-
P. Hooimeijer, B. Livshits, D. Molnar, P. Saxena, and M. Veanes. Fast and precise sanitizer analysis with BEK. In Proceedings of the Usenix Security Symposium, 2011.
-
(2011)
Proceedings of the Usenix Security Symposium
-
-
Hooimeijer, P.1
Livshits, B.2
Molnar, D.3
Saxena, P.4
Veanes, M.5
-
24
-
-
79951589262
-
Securing web application code by static analysis and runtime protection
-
WWW '04
-
Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D.-T. Lee, and S.-Y. Kuo. Securing web application code by static analysis and runtime protection. In Proceedings of the 13th international conference on World Wide Web, WWW '04.
-
Proceedings of the 13th International Conference on World Wide Web
-
-
Huang, Y.-W.1
Yu, F.2
Hang, C.3
Tsai, C.-H.4
Lee, D.-T.5
Kuo, S.-Y.6
-
25
-
-
80053065711
-
-
JiftyManual. http://jifty.org/view/JiftyManual.
-
JiftyManual
-
-
-
29
-
-
85008256304
-
HAMPI: A solver for string constraints
-
A. Kieżun, V. Ganesh, P. J. Guo, P. Hooimeijer, and M. D. Ernst. HAMPI: A solver for string constraints. In International Symposium on Software Testing and Analysis, 2009.
-
(2009)
International Symposium on Software Testing and Analysis
-
-
Kiezun, A.1
Ganesh, V.2
Guo, P.J.3
Hooimeijer, P.4
Ernst, M.D.5
-
33
-
-
85084163766
-
Automatic generation of XSS and SQL injection attacks with goal-directed model checking
-
M. Martin and M. S. Lam. Automatic generation of XSS and SQL injection attacks with goal-directed model checking. In 17th USENIX Security Symposium, 2008.
-
(2008)
17th USENIX Security Symposium
-
-
Martin, M.1
Lam, M.S.2
-
34
-
-
80755159889
-
-
The Mason Book: Escaping Substitutions. http://www.masonbook.com/book/ chapter-2.mhtml.
-
Escaping Substitutions
-
-
-
35
-
-
77955186827
-
ConScript: Specifying and enforcing fine-grained security policies for JavaScript in the browser
-
May
-
L. Meyerovich and B. Livshits. ConScript: Specifying and enforcing fine-grained security policies for JavaScript in the browser. In IEEE Symposium on Security and Privacy, May 2010.
-
(2010)
IEEE Symposium on Security and Privacy
-
-
Meyerovich, L.1
Livshits, B.2
-
36
-
-
78650896178
-
Document structure integrity: A robust basis for cross-site scripting defense
-
Y. Nadji, P. Saxena, and D. Song. Document structure integrity: A robust basis for cross-site scripting defense. In NDSS, 2009.
-
(2009)
NDSS
-
-
Nadji, Y.1
Saxena, P.2
Song, D.3
-
37
-
-
84871349041
-
Automatically hardening web applications using precise tainting
-
A. Nguyen-Tuong, S. Guarnieri, D. Greene, J. Shirley, and D. Evans. Automatically hardening web applications using precise tainting. 20th IFIP International Information Security Conference, 2005.
-
(2005)
20th IFIP International Information Security Conference
-
-
Nguyen-Tuong, A.1
Guarnieri, S.2
Greene, D.3
Shirley, J.4
Evans, D.5
-
38
-
-
80053075919
-
-
XSS Prevention Cheat Sheet. http://www.owasp.org/index.php/XSS-(Cross- Site-Scripting)-Prevention-Cheat-Sheet.
-
XSS Prevention Cheat Sheet
-
-
-
39
-
-
80053079139
-
Static enforcement of web application integrity through strong typing
-
Montreal, Canada, August
-
W. Robertson and G. Vigna. Static Enforcement of Web Application Integrity Through Strong Typing. In Proceedings of the USENIX Security Symposium, Montreal, Canada, August 2009.
-
(2009)
Proceedings of the USENIX Security Symposium
-
-
Robertson, W.1
Vigna, G.2
-
40
-
-
80755172920
-
-
Ruby on Rails Security Guide. http://guides.rubyonrails.org/security. html.
-
Security Guide
-
-
-
41
-
-
77955220343
-
A symbolic execution framework for JavaScript
-
University of California, Berkeley
-
P. Saxena, D. Akhawe, S. Hanna, F. Mao, S. McCamant, and D. Song. A symbolic execution framework for JavaScript. Technical Report UCB/EECS-2010-26, EECS Department, University of California, Berkeley, 2010.
-
(2010)
Technical Report UCB/EECS-2010-26, EECS Department
-
-
Saxena, P.1
Akhawe, D.2
Hanna, S.3
Mao, F.4
Mccamant, S.5
Song, D.6
-
42
-
-
80051946867
-
FLAX: Systematic discovery of client-side validation vulnerabilities in rich web applications
-
P. Saxena, S. Hanna, P. Poosankam, and D. Song. FLAX: Systematic discovery of client-side validation vulnerabilities in rich web applications. In 17th Annual Network & Distributed System Security Symposium, (NDSS), 2010.
-
(2010)
17th Annual Network & Distributed System Security Symposium, (NDSS)
-
-
Saxena, P.1
Hanna, S.2
Poosankam, P.3
Song, D.4
-
44
-
-
80755159885
-
-
Smarty Template Engine: escape. http://www.smarty.net/manual/en/language. modifier.escape.php.
-
Escape
-
-
-
45
-
-
85029460807
-
-
Google Closure Templates. http://code.google.com/closure/templates/.
-
Closure Templates
-
-
-
48
-
-
80755173822
-
-
Template: Manual: Filters. http://template-toolkit.org/docs/manual/ Filters.html.
-
Manual: Filters
-
-
-
50
-
-
84869476644
-
A systematic analysis of XSS sanitization in web application frameworks
-
J. Weinberger, P. Saxena, D. Akhawe, M. Finifter, R. Shin, and D. Song. A Systematic Analysis of XSS Sanitization in Web Application Frameworks. In Proceedings of the European Symposium on Research in Computer Security, 2011.
-
(2011)
Proceedings of the European Symposium on Research in Computer Security
-
-
Weinberger, J.1
Saxena, P.2
Akhawe, D.3
Finifter, M.4
Shin, R.5
Song, D.6
-
52
-
-
85038810709
-
Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks
-
W. Xu, S. Bhatkar, and R. Sekar. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. USENIX Security Symposium, 2006.
-
(2006)
USENIX Security Symposium
-
-
Xu, W.1
Bhatkar, S.2
Sekar, R.3
-
53
-
-
80755127548
-
-
Yii Framework: Security. http://www.yiiframework.com/doc/guide/1.1/en/ topics.security.
-
Security
-
-
-
54
-
-
80755173830
-
-
Zend Framework: Zend Filter. http://framework.zend.com/manual/en/zend. filter.set.html.
-
Zend Filter
-
-
|