I forgot to blog about one of my projects. I had actually already talked about it more than one year ago and we had a paper at USENIX Security. Essentially, we built a protection against DOM-based Cross-site Scripting (DOMXSS) into Chromium. We did that by detecting whenever potentially attacker provided strings become JavaScript code. To that end, we made the HTML rendering engine (WebKit/Blink)


{{#tags}}- {{label}}
{{/tags}}