Programming Languages White Papers

Using Web Application Construction Frameworks to Protect Against Code Injection Attacks

Overview This paper proposes a simple to support, yet a powerful scheme for eliminating a wide range of script injection vulnerabilities in applications built on top of popular Ajax development frameworks such as the Dojo Toolkit, prototype.js, and AJAX.NET. Unlike other client-side runtime enforcement proposals, the approach it is advocating requires only minor browser modifications. This is because the proposal can be viewed as a natural finer-grained extension of the same-origin policy for JavaScript already supported by the majority of mainstream browsers, in which it treat individual user interface widgets as belonging to separate domains.

Further White Paper Details
PublisherAssociation for Computing Machinery File FormatPDF
Date PublishedMay 2007
FormatWhite Papers   
Topics

Quick Sitemap Links: