Published June 27, 2018 | Version v1

Cross-Origin Vulnerabilities in Web Sites: Detection & Prevention

  • 1. IMDEA Software Institute

Description

Web browsers support various cross-origin interaction features including cross-origin resource inclusion and cross-origin resource sharing. These features can be abused to mount various cross-origin attacks (e.g., cross-site request forgery, cross-site script inclusion, etc.).

Many client-side and server-side defenses have been proposed against cross-origin attacks (e.g., SameSite cookies, Cross-Origin Resource Policy, Cross-Origin Window Policy etc.). However, incorrect implementation of these defenses is a big problem.

In this poster, we propose the need for a framework that can assist developers in identifying cross-origin attacks, understanding how to fix them, and test whether the fix has been implemented correctly.

Files

Google Web Sec Summit Poster.pdf

Files (129.3 kB)

Name Size Download all
md5:c56759869a49594b7a5b3181f1e82484
129.3 kB Preview Download

Additional details

Funding

European Commission
ELASTEST - ElasTest: an elastic platform for testing complex distributed large software systems 731535