Software

Language-Based Isolation of Untrusted JavaScript

Download Now Free registration required

Executive Summary

Web sites that incorporate untrusted content may use browser- or language-based methods to keep such content from maliciously altering pages, stealing sensitive information, or causing other harm. The authors study language based methods for filtering and rewriting JavaScript code, using Yahoo! ADSafe and Facebook FBJS as motivating examples. They explain the core problems by describing previously unknown vulnerabilities and subtleties, and develop a foundation for improved solutions based on an operational semantics of the full ECMA-262 language.

  • Format: PDF
  • Size: 483.3 KB