Detecting and understanding JavaScript global identifier conflicts on the web
Mingxue Zhang, Wei Meng
Abstract
JavaScript is widely used for implementing client-side web applications, and it is common to include JavaScript code from many different hosts. However, in a web browser, all the scripts loaded in the same frame share a single global namespace. As a result, a script may read or even overwrite the global objects or functions in other scripts, causing unexpected behaviors. For example, a script can redefine a function in a different script as an object, so that any call of that function would cause an exception at run time.
We systematically investigate the client-side JavaScript code integrity problem caused by JavaScript global identifier conflicts in this paper. We developed a browser-based analysis framework, JSObserver, to collect and analyze the write operations to global memory locations by JavaScript code. We identified three categories of conflicts using JSObserver on the Alexa top 100K websites, and detected 145,918 conflicts on 31,615 websites.
We reveal that JavaScript global identifier conflicts are prevalent and could cause behavior deviation at run time. In particular, we discovered that 1,611 redefined functions were called after being overwritten, and many scripts modified the value of cookies or redefined cookie-related functions. Our research demonstrated that JavaScript global identifier conflict is an emerging threat to both the web users and the integrity of web applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7af1b7b2-591d-4834-b5d7-2870bec36ceeCited by top-tier papers6
- JSISOLATE: lightweight in-browser JavaScript isolationMingxue Zhang, Wei MengFSE 2021 · 9 citations
- PURL: Safe and Effective Sanitization of Link DecorationShaoor Munir, Patrick Lee, Umar Iqbal, Sandra Deepthy Siby et al.USENIX Security 2024 · 9 citations
- CoCo: Efficient Browser Extension Vulnerability Detection via Coverage-guided, Concurrent Abstract InterpretationJianjia Yu, Song Li, Junmin Zhu, Yinzhi CaoCCS 2023 · 6 citations
- ReactAppScan: Mining React Application Vulnerabilities via Component GraphZhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo et al.CCS 2024 · 3 citations
- Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityMingqing Kang, Yichao Xu, Song Li, Rigel Gjomemo et al.S&P 2023
Builds on2
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- Content Security Problems?: Evaluating the Effectiveness of Content Security Policy in the WildStefano Calzavara, Alvise Rabitti, Michele BugliesiCCS 2016 · 71 citations
Related papers
- All Your Clicks Belong to Me: Investigating Click Interception on the WebMingxue Zhang, Wei Meng, Sangho Lee, Byoungyoung Lee et al.USENIX Security 2019 · 26 citations
- The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's PerspectiveAndrea Mengascini, Ryan Aurelio, Giancarlo PellegrinoCCS 2024
- Cookie Swap Party: Abusing First-Party Cookies for Web TrackingQuan Chen, Panagiotis Ilia, Michalis Polychronakis, Alexandros KapravelosWWW 2021 · 57 citations
- Detecting and Understanding Self-Deleting JavaScript CodeXinzhe Wang, Zeyang Zhuang, Wei Meng, James ChengWWW 2024
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
