Up a level |
(2024) The Great Request Robbery: An Empirical Study of Client-side Request Hijacking Vulnerabilities on the Web.
(2023) It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and Defenses.
(2022) The State of the SameSite: Studying the Usage, Effectiveness, and Adequacy of SameSite Cookies.
(2021) Where We Stand (or Fall): An Analysis of CSRF Defenses in Web Frameworks.
(2021) JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative Traversals.
(2020) Cross-Origin State Inference (COSI) Attacks: Leaking Web Site States through XS-Leaks.