Skip to main content

Showing 1–2 of 2 results for author: Steinhauser, A

Searching in archive cs. Search in all archives.
.
  1. DjangoChecker: Applying Extended Taint Tracking and Server Side Parsing for Detection of Context-Sensitive XSS Flaws

    Authors: Antonín Steinhauser, Petr Tůma

    Abstract: Cross-site scripting (XSS) flaws are a class of security flaws that permit the injection of malicious code into a web application. In simple situations, these flaws can be caused by missing input sanitizations. Sometimes, however, all application inputs are sanitized, but the sanitizations are not appropriate for the browser contexts of the sanitized values. Using an incorrect sanitizer can make t… ▽ More

    Submitted 14 May, 2020; originally announced May 2020.

    Journal ref: Software: Practice and Experience, 49(1): 130-148, 2019

  2. Database Traffic Interception for Graybox Detection of Stored and Context-Sensitive XSS

    Authors: Antonín Steinhauser, Petr Tůma

    Abstract: XSS is a security vulnerability that permits injecting malicious code into the client side of a web application. In the simplest situations, XSS vulnerabilities arise when a web application includes the user input in the web output without due sanitization. Such simple XSS vulnerabilities can be detected fairly reliably with blackbox scanners, which inject malicious payload into sensitive parts of… ▽ More

    Submitted 7 August, 2020; v1 submitted 7 May, 2020; originally announced May 2020.

    Journal ref: Digital Threats: Research and Practice, 1(3): 1-23, 2020