Martin Johns
4 papers in the PaperMetrix corpus
Papers by this author
-
Code-Reuse Attacks for the Web
2017
Cross-Site Scripting (XSS) is an unremitting problem for the Web. Since its initial public documentation in 2000 until now, XSS has been continuously on top of the vulnerability statistics. Even though there has been a …
-
ScriptProtect
2019
The direct client-side inclusion of cross-origin JavaScript resources in Web applications is a pervasive practice to consume third-party services and to utilize externally provided libraries. The downside of this practice is that such external code …
-
General Data Protection Runtime: Enforcing Transparent GDPR Compliance for Existing Applications
2023
Recent advances in data protection regulations brings privacy benefits for website users, but also comes at a cost for operators. Retrofitting the privacy requirements of laws such as the General Data Protection Regulation (GDPR) onto …
-
Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials
2024
Websites rely on server-side HTML sanitization to defend against the ever-present threat of cross-site scripting attacks. Parsing arbitrary pieces of markup to assess whether they contain an exploit payload is far from trivial. This complexity …