Attacking and defending JavaScript sandboxes
portswigger.net | research | #web-security | #sandbox-escape | #proxy | #defense | #code-execution | #javascript-sandbox
Summary
Attacking and defending JavaScript sandboxes: with-statement breakouts, prototype tampering and generator constructors defeat naive proxy sandboxes; checkSyntax and a hardened design are proposed.
- Published
- Collected
Skip to content