Sebastian Lekies
YOU?
Author Swipe
View article: No keys to the kingdom required
No keys to the kingdom required Open
Nowadays, applications expose administrative endpoints to the Web that can be used for a plethora of security sensitive actions. Typical use cases range from running small snippets of user-provided code for rapid prototyping, administering…
View article: Code-Reuse Attacks for the Web
Code-Reuse Attacks for the Web Open
Cross-Site Scripting (XSS) is an unremitting problem for the Web. Since its initial public documentation in 2000 until now, XSS has been continuously on top of the vulnerability statistics. Even though there has been a considerable amount …
View article: CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy
CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security Policy Open
Content Security Policy is a web platform mechanism designed to mitigate cross-site scripting (XSS), the top security vulnerability in modern web applications. In this paper, we take a closer look at the practical benefits of adopting CSP …