14
IRUS TotalDownloads
Altmetric
Language-based isolation of untrusted JavaScript
File | Description | Size | Format | |
---|---|---|---|---|
DTR09-3.pdf | Published version | 483.33 kB | Adobe PDF | View/Open |
Title: | Language-based isolation of untrusted JavaScript |
Authors: | Maffeis, S Mitchell, JC Taly, A |
Item Type: | Report |
Abstract: | Web sites that incorporate untrusted content may use browser- or language-based methods to keep such content from maliciously altering pages, stealing sensitive information, or causing other harm. We study languagebased methods for ltering and rewriting JavaScript code, using Yahoo! ADSafe and Facebook FBJS as motivating examples. We explain the core problems by describing previously unknown vulnerabilities and subtleties, and develop a foundation for improved solutions based on an operational semantics of the full ECMA-262 language.We also discuss how to apply our analysis to address the JavaScript isolation problems we discovered. |
Issue Date: | 1-Jan-2009 |
URI: | http://hdl.handle.net/10044/1/95274 |
DOI: | https://doi.org/10.25561/95274 |
Publisher: | Department of Computing, Imperial College London |
Start Page: | 1 |
End Page: | 36 |
Journal / Book Title: | Departmental Technical Report: 09/3 |
Copyright Statement: | © 2009 The Author(s). This report is available open access under a CC-BY-NC-ND (https://creativecommons.org/licenses/by-nc-nd/4.0/) |
Publication Status: | Published |
Article Number: | 09/3 |
Appears in Collections: | Computing Computing Technical Reports |
This item is licensed under a Creative Commons License