kirancodes.me
To Proof Maintenance & Beyond!

Auto-patching DOM-based XSS at scale

Inian Parameshwaran, Enrico Budianto, Shweta Shinde, Hung Dang, Atul Sadhu, Prateek Saxena

Abstract

DOM-based cross-site scripting (XSS) is a client-side code injection vulnerability that results from unsafe dynamic code generation in JavaScript applications, and has few known practical defenses. We study dynamic code evaluation practices on nearly a quarter million URLs crawled starting from the the Alexa Top 1000 websites. Of 777,082 cases of dynamic HTML/JS code generation we observe, 13.3% use unsafe string interpolation for dynamic code generation — a well-known dangerous coding practice. To remedy this, we propose a technique to generate secure patches that replace unsafe string interpolation with safer code that utilizes programmatic DOM construction techniques. Our system transparently auto-patches the vulnerable site while incurring only 5.2 − 8.07% overhead. The patching mechanism requires no access to server-side code or modification to browsers, and thus is practical as a turnkey defense.

BibTeX
@inproceedings{Parameshwaran-al:FSE15,
  author    = {Inian Parameshwaran and
               Enrico Budianto and
               Shweta Shinde and
               Hung Dang and
               Atul Sadhu and
               Prateek Saxena},
  title     = {Auto-patching {DOM-based} {XSS} at scale},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {272--283},
  publisher = {{ACM}},
  year      = {2015},
}

Related papers