Characterizing insecure javascript practices on the web

Chuan Yue, Haining Wang

2009 · 108 citations · 27 references

Concepts

TL;DR

JavaScript, an interpreted language widely used to enhance webpage interactivity, offers powerful capabilities that also enable browser‑based security attacks, and insecure engineering practices can create new attack vectors and amplify the risk of such attacks. This study presents the first measurement of insecure JavaScript practices on the Web. The authors examined insecure JavaScript inclusion and dynamic generation practices across 6,805 unique websites, assessing their severity and nature. The study found that insecure practices are widespread—66.4 % of sites include external JavaScript files, 44.4 % use eval(), and document.write() and innerHTML are more common than safe DOM methods—yet safe alternatives exist and should be adopted to reduce risks.

Abstract

JavaScript is an interpreted programming language most often used for enhancing webpage interactivity and functionality. It has powerful capabilities to interact with webpage documents and browser windows, however, it has also opened the door for many browser-based security attacks. Insecure engineering practices of using JavaScript may not directly lead to security breaches, but they can create new attack vectors and greatly increase the risks of browser-based attacks. In this paper, we present the first measurement study on insecure practices of using JavaScript on the Web. Our focus is on the insecure practices of JavaScript inclusion and dynamic generation, and we examine their severity and nature on 6,805 unique websites. Our measurement results reveal that insecure JavaScript practices are common at various websites: (1) at least 66.4% of the measured websites manifest the insecure practices of including JavaScript files from external domains into the top-level documents of their webpages; (2) over 44.4% of the measured websites use the dangerous eval() function to dynamically generate and execute JavaScript code on their webpages; and (3) in JavaScript dynamic generation, using the document.write() method and the innerHTML property is much more popular than using the relatively secure technique of creating script elements via DOM methods. Our analysis indicates that safe alternatives to these insecure practices exist in common cases and ought to be adopted by website developers and administrators for reducing potential security risks.

References

27