2009 · 108 citations · 27 references
Hardware SecurityInternet SecuritySoftware SecurityEngineeringUsable SecurityInformation SecurityProgram AnalysisWeb SecuritySecure By DesignData PrivacySecurityInsecure Javascript PracticesLanguage-based SecurityJavascript Dynamic GenerationInterpreted Programming LanguageDynamic Web PageData SecurityPotential Security Risks
JavaScript, an interpreted language widely used to enhance webpage interactivity, offers powerful capabilities that also enable browser‑based security attacks, and insecure engineering practices can create new attack vectors and amplify the risk of such attacks. This study presents the first measurement of insecure JavaScript practices on the Web. The authors examined insecure JavaScript inclusion and dynamic generation practices across 6,805 unique websites, assessing their severity and nature. The study found that insecure practices are widespread—66.4 % of sites include external JavaScript files, 44.4 % use eval(), and document.write() and innerHTML are more common than safe DOM methods—yet safe alternatives exist and should be adopted to reduce risks.
JavaScript is an interpreted programming language most often used for enhancing webpage interactivity and functionality. It has powerful capabilities to interact with webpage documents and browser windows, however, it has also opened the door for many browser-based security attacks. Insecure engineering practices of using JavaScript may not directly lead to security breaches, but they can create new attack vectors and greatly increase the risks of browser-based attacks. In this paper, we present the first measurement study on insecure practices of using JavaScript on the Web. Our focus is on the insecure practices of JavaScript inclusion and dynamic generation, and we examine their severity and nature on 6,805 unique websites. Our measurement results reveal that insecure JavaScript practices are common at various websites: (1) at least 66.4% of the measured websites manifest the insecure practices of including JavaScript files from external domains into the top-level documents of their webpages; (2) over 44.4% of the measured websites use the dangerous eval() function to dynamically generate and execute JavaScript code on their webpages; and (3) in JavaScript dynamic generation, using the document.write() method and the innerHTML property is much more popular than using the relatively secure technique of creating script elements via DOM methods. Our analysis indicates that safe alternatives to these insecure practices exist in common cases and ought to be adopted by website developers and administrators for reducing potential security risks.
27
Clone detection using abstract syntax trees
Ira D. Baxter, A. Yahin, Leonardo de Moura et al. · 2002 · 1.3K citations
Securing web application code by static analysis and runtime protection
Yao‐Wen Huang, Fang Yu, Christian Hang et al. · 2004 · 564 citations
Web data extraction based on partial tree alignment
Yanhong Zhai, Bing Liu · 2005 · 495 citations
Niels Provos, Panayiotis Mavrommatis, Moheeb Abu Rajab et al. · 2008 · 480 citations
Robust defenses for cross-site request forgery
Adam Barth, Collin Jackson, John C. Mitchell · 2008 · 409 citations