Up a level |
(2022) Hand Sanitizers in the Wild: A Large-scale Study of Custom JavaScript Sanitizer Functions.
(2021) Who's Hosting the Block Party? Studying Third-Party Blockage of CSP and SRI.
(2020) Raccoon: Automated Verification of Guarded Race Conditions in Web Applications.
(2019) ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices.
(2019) Don’t Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the Wild.
(2017) How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)Security.
(2017) Deemon: Detecting CSRF with Dynamic Analysis and Property Graphs.
(2016) Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability Notification.
(2016) POSTER: Mapping the Landscape of Large-Scale Vulnerability Notifications.
(2015) From Facepalm to Brain Bender: Exploring Client-Side Cross-Site Scripting.
(2015) The Unexpected Dangers of Dynamic JavaScript.
(2014) Precise Client-side Protection against DOM-based Cross-Site Scripting.
(2014) DOM-basiertes Cross-Site Scripting im Web: Reise in ein unerforschtes Land.
(2014) Protecting Users Against XSS-based Password Manager Abuse.
(2013) 25 Million Flows Later - Large-scale Detection of DOM-based XSS.
(2013) Eradicating DNS Rebinding with the Extended Same-Origin Policy.