MatriXSSed: A New Taxonomy for XSS in the Modern Web
Dolière Francis Somé
Abstract
Cross-site scripting (XSS) has constantly remained one of the most prevalent attacks on the Web. In this work, we question its current taxonomy, i.e., the client- or server-side reflected (non-persistent) or stored (persistent) matrix. The Web has extensively changed. Consequently, considering XSS with the lenses of this famous matrix has become at least imprecise, at most impossible for many code injection scenarios where (i) a service worker or an edge worker generates HTTP responses and can reflect or persist XSS payloads infecting not only JavaScript in web pages but also Web assembly, web workers and affecting one or many users automatically; (ii) an attacker sends a web push message directly to a browser push service to trigger code execution in a dormant service worker; or (iii) a cross-origin adversary tampers with code stored by a vulnerable website on the user's physical/permanent file system, etc. Our proposal --to get out of the matrix and not enter another rigid one-- expresses the essence of XSS as code infection and affection attack and allows for clearly specifying the different actors and components involved, their environments, contexts, and storages, as well as their recurrence and persistence seen as a continuum rather than a binary marker. From a defensive perspective, we showcase the challenges and limitations of current mechanisms for mitigating XSS, which targets the entire attack surface of modern websites. Finally, we demonstrate an abuse of the Service-Worker-Allowed header to control entire domains with malicious service workers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8405c684-2d48-430d-968f-9d327f73379cBuilds on11
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- Code-Reuse Attacks for the Web: Breaking Cross-Site Scripting Mitigations via Script GadgetsSebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava et al.CCS 2017 · 62 citations
- PMForce: Systematically Analyzing postMessage Handlers at ScaleMarius Steffens, Ben StockCCS 2020 · 23 citations
- CCSP: Controlled Relaxation of Content Security Policies by Runtime Policy CompositionStefano Calzavara, Alvise Rabitti, Michele BugliesiUSENIX Security 2017 · 15 citations
Related papers
- SWAPP: A New Programmable Playground for Web Application SecurityPhakpoom Chinprutthiwong, Jianwei Huang, Guofei GuUSENIX Security 2022
- Splendor: Static Detection of Stored XSS in Modern Web ApplicationsHe Su, Feng Li, Lili Xu, Wenbo Hu et al.ISSTA 2023 · 11 citations
- From Payload to Plugin: Web-Scale Ecosystem Attribution of JavaScript Injection CampaignsRavindu De Silva, Nicholas Shao, Yigitcan Kaya, Mingxuan Yao et al.CCS 2026
- Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform EcosystemFeng Xiao, Zheng Yang, Joey Allen, Guangliang Yang et al.CCS 2022 · 14 citations
- Dancer in the Dark: Synthesizing and Evaluating Polyglots for Blind Cross-Site ScriptingRobin Kirchner, Jonas Möller, Marius Musch, David Klein et al.USENIX Security 2024 · 9 citations
