Cross-Origin Vulnerabilities in Web Sites: Detection & Prevention
Description
Web browsers support various cross-origin interaction features including cross-origin resource inclusion and cross-origin resource sharing. These features can be abused to mount various cross-origin attacks (e.g., cross-site request forgery, cross-site script inclusion, etc.).
Many client-side and server-side defenses have been proposed against cross-origin attacks (e.g., SameSite cookies, Cross-Origin Resource Policy, Cross-Origin Window Policy etc.). However, incorrect implementation of these defenses is a big problem.
In this poster, we propose the need for a framework that can assist developers in identifying cross-origin attacks, understanding how to fix them, and test whether the fix has been implemented correctly.
Files
Google Web Sec Summit Poster.pdf
Files
(129.3 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:c56759869a49594b7a5b3181f1e82484
|
129.3 kB | Preview Download |