awesome-web-security-paper
awesome-web-security-paper copied to clipboard
π Web security related academic papers collection (just for myself).
trafficstars
Awesome Web Security Papers
Web security related academic papers collection (just for myself).
Abusing Hidden Properties to Attack the Node.js Ecosystem
- Tags:
JavaScript - Conference: USENIX Security @ 2021
JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals
- Tags:
CSRFFrontend - Conference: USENIX Security @ 2021
Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel Defenses
- Tags:
FrontendSide-channel - Conference: USENIX Security @ 2021
Saphire: Sandboxing PHP Applications with Tailored System Call Allowlists
- Tags:
PHPSandbox - Conference: USENIX Security @ 2021
Everything Old is New Again: Binary Security of WebAssembly
- Tags:
WebAssembly - Conference: USENIX Security @ 2020
Cached and Confused: Web Cache Deception in the Wild
- Tags:
Cache Deception - Conference: USENIX Security @ 2020
Leaky Images: Targeted Privacy Attacks in the Web
- Tags:
Side-channelXS-Leaks - Conference: USENIX Security @ 2019
What Are You Searching For? A Remote Keylogging Attack on Search Engine Autocomplete
- Tags: ``
- Conference: USENIX Security @ 2019
NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications
- Tags:
Exploit generationSymbolic - Conference: USENIX Security @ 2018
SerialDetector: Principled and Practical Exploration of Object Injection Vulnerabilities for the Web
- Tags:
.NETDeserialization - Conference: NDSS @ 2021
The Cookie Hunter: Automated Black-box Auditing for Web Authentication and Authorization Flaws
- Tags:
AuthBlackbox - Conference: NDSS @ 2020
FUSE: Finding File Upload Bugs via Penetration Testing
- Tags:
PHPUpload - Conference: NDSS @ 2020
Donβt Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the Wild
- Tags:
FrontendXSS - Conference: NDSS @ 2019
Riding out DOMsday: Toward Detecting and Preventing DOM Cross-Site Scripting
- Tags:
FrontendXSS - Conference: NDSS @ 2018
Synode: Understanding and Automatically Preventing Injection Attacks on Node.js
- Tags:
JavaScript - Conference: NDSS @ 2018
PMForce: Systematically Analyzing postMessage Handlers at Scale
- Tags:
Frontend - Conference: ACM CCS @ 2020
MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis
- Tags:
PHPWebshell - Conference: ACM CCS @ 2019
Black Widow: Blackbox Data-driven Web Scanning
- Tags:
BlackboxScanner - Conference: IEEE S&P @ 2021
Revealer: Detecting and Exploiting Regular Expression Denial-of-Service Vulnerabilities
- Tags:
ReDoS - Conference: IEEE S&P @ 2021
Runtime Recovery of Web Applications under Zero-Day ReDoS Attacks
- Tags:
ReDoS - Conference: IEEE S&P @ 2021