Cross-site scripting (XSS) attacks keep plaguing the Web. Supported by most modern browsers, Content Security Policy (CSP) prescribes the browser to restrict the features and communication capabilities of code on a web page, mitigating the effects of XSS. This paper puts a spotlight on the problem of data exfiltration in the face of CSP. We bring attention to the unsettling discord in the security community about the very goals of CSP when it comes to preventing data leaks. As consequences of this discord, we report on insecurities in the known protection mechanisms that are based on assumptions about CSP that turn out not to hold in practice. To illustrate the practical impact of the discord, we perform a systematic case study of data exfi...
We investigate data exfiltration by third-party scripts directly embedded on web pages. Specifically...
More and more people use the Web on a daily basis. We use it for communicating, doing bank transacti...
Content Security Policy (CSP) is an emerging W3C standard introduced to mitigate the impact of conte...
Cross-site scripting (XSS) attacks keep plaguing the Web. Supported by most modern browsers, Content...
Abstract. Content Security Policy (CSP) has been proposed as a prin-cipled and robust browser securi...
Cross-site scripting (XSS) vulnerabilities are among the most prevailing problems on the web. Among ...
Content Security Policy (CSP) is powerful client-side security layer that helps in mitigating and de...
A content security policy (CSP) can help Web application developers and server administrators better...
Abstract. Cross-site scripting (XSS) vulnerabilities are among the most prevailing problems on the w...
The Web, as one of the core technologies of modern society, has profoundly changed the way we intera...
The Content Security Policy (CSP) mechanism was developed as a mitigation against script injection a...
The Web has improved our ways of communicating, collaborating, teaching, and entertaining us and our...
Protecting users in the ubiquitous online world is becoming more and more important, as shown by web...
The Content Security Policy (CSP) mechanism was developed as a mitigation against script injection a...
Cross-site scripting (XSS) is an attack against web applications in which scripting code is injected...
We investigate data exfiltration by third-party scripts directly embedded on web pages. Specifically...
More and more people use the Web on a daily basis. We use it for communicating, doing bank transacti...
Content Security Policy (CSP) is an emerging W3C standard introduced to mitigate the impact of conte...
Cross-site scripting (XSS) attacks keep plaguing the Web. Supported by most modern browsers, Content...
Abstract. Content Security Policy (CSP) has been proposed as a prin-cipled and robust browser securi...
Cross-site scripting (XSS) vulnerabilities are among the most prevailing problems on the web. Among ...
Content Security Policy (CSP) is powerful client-side security layer that helps in mitigating and de...
A content security policy (CSP) can help Web application developers and server administrators better...
Abstract. Cross-site scripting (XSS) vulnerabilities are among the most prevailing problems on the w...
The Web, as one of the core technologies of modern society, has profoundly changed the way we intera...
The Content Security Policy (CSP) mechanism was developed as a mitigation against script injection a...
The Web has improved our ways of communicating, collaborating, teaching, and entertaining us and our...
Protecting users in the ubiquitous online world is becoming more and more important, as shown by web...
The Content Security Policy (CSP) mechanism was developed as a mitigation against script injection a...
Cross-site scripting (XSS) is an attack against web applications in which scripting code is injected...
We investigate data exfiltration by third-party scripts directly embedded on web pages. Specifically...
More and more people use the Web on a daily basis. We use it for communicating, doing bank transacti...
Content Security Policy (CSP) is an emerging W3C standard introduced to mitigate the impact of conte...