{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,4,29]],"date-time":"2024-04-29T14:34:34Z","timestamp":1714401274049},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2023,8,17]],"date-time":"2023-08-17T00:00:00Z","timestamp":1692230400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,8,17]],"date-time":"2023-08-17T00:00:00Z","timestamp":1692230400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2023,9]]},"DOI":"10.1007\/s10664-023-10323-w","type":"journal-article","created":{"date-parts":[[2023,8,17]],"date-time":"2023-08-17T04:02:33Z","timestamp":1692244953000},"update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["XSnare: application-specific client-side cross-site scripting protection"],"prefix":"10.1007","volume":"28","author":[{"given":"Jos\u00e9 Carlos","family":"Pazos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean-S\u00e9bastien","family":"L\u00e9gar\u00e9","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ivan","family":"Beschastnikh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,8,17]]},"reference":[{"key":"10323_CR1","doi-asserted-by":"publisher","unstructured":"Abgrall E, Traon YL, Gombault S, et\u00a0al (2014) Empirical investigation of the web browser attack surface under cross-site scripting: An urgent need for systematic security regression testing. In: 2014 IEEE Seventh International Conference on Software Testing, Verification and Validation Workshops. pp 34\u201341. https:\/\/doi.org\/10.1109\/ICSTW.2014.63","DOI":"10.1109\/ICSTW.2014.63"},{"key":"10323_CR2","unstructured":"Acu (2021) Acunetix web vulnerability testing report 2021. https:\/\/www.acunetix.com\/white-papers\/acunetix-web-application-vulnerability-report-2021\/"},{"key":"10323_CR3","unstructured":"adb (2018) How does adblock work? https:\/\/help.getadblock.com\/support\/solutions\/articles\/6000087914-how-does-adblock-work-"},{"issue":"4","key":"10323_CR4","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1109\/TSE.2010.31","volume":"36","author":"S Artzi","year":"2010","unstructured":"Artzi S, Kiezun A, Dolby J et al (2010) Finding bugs in web applications using dynamic test generation and explicit-state model checking. IEEE Trans Softw Eng 36(4):474\u2013494. https:\/\/doi.org\/10.1109\/TSE.2010.31","journal-title":"IEEE Trans Softw Eng"},{"key":"10323_CR5","doi-asserted-by":"publisher","unstructured":"Bezemer CP, Mesbah A, van Deursen A (2009) Automated security testing of web widget interactions. In: Proceedings of the 7th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on The Foundations of Software Engineering. Association for Computing Machinery, New York, NY, USA, ESEC\/FSE \u201909. pp 81-90. https:\/\/doi.org\/10.1145\/1595696.1595711","DOI":"10.1145\/1595696.1595711"},{"key":"10323_CR6","doi-asserted-by":"publisher","unstructured":"Bisht P, Venkatakrishnan VN (2008) XSS-GUARD: Precise dynamic prevention of cross-site scripting attacks. In: Proceedings of the 5th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. Springer-Verlag, Berlin, Heidelberg, DIMVA \u201908. pp 23\u201343. https:\/\/doi.org\/10.1007\/978-3-540-70542-0_2","DOI":"10.1007\/978-3-540-70542-0_2"},{"key":"10323_CR7","unstructured":"CSP (2019) Same-origin policy. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Security\/Same-origin_policy"},{"key":"10323_CR8","unstructured":"cve (2019a) Wordpress cves. https:\/\/cve.mitre.org\/cgi-bin\/cvekey.cgi?keyword=wordpress"},{"key":"10323_CR9","unstructured":"cve (2019b) Wordpress: Vulnerability statistics. https:\/\/www.cvedetails.com\/product\/4096\/Wordpress-Wordpress.html?vendor_id=2337"},{"key":"10323_CR10","unstructured":"dep (2019) Intent to deprecate and remove: XSSAuditor. https:\/\/groups.google.com\/a\/chromium.org\/forum\/#!msg\/blink-dev\/TuYw-EZhO9g\/blGViehIAwAJ"},{"key":"10323_CR11","unstructured":"exa (2018) Wordpress plugin responsive cookie consent 1.7 \/ 1.6 \/ 1.5 - (authenticated) persistent cross-site scripting. https:\/\/www.exploit-db.com\/exploits\/44563"},{"key":"10323_CR12","unstructured":"exp (2019) Exploit database. https:\/\/www.exploit-db.com\/"},{"key":"10323_CR13","doi-asserted-by":"publisher","unstructured":"Hallaraker O, Vigna G (2005) Detecting malicious javascript code in mozilla. In: Proceedings of the 10th IEEE International Conference on Engineering of Complex Computer Systems. IEEE Computer Society, Washington, DC, USA, ICECCS \u201905, pp 85\u201394. https:\/\/doi.org\/10.1109\/ICECCS.2005.35","DOI":"10.1109\/ICECCS.2005.35"},{"key":"10323_CR14","doi-asserted-by":"publisher","first-page":"116","DOI":"10.1007\/978-3-319-66399-9_7","volume-title":"Computer Security - ESORICS 2017","author":"M Heiderich","year":"2017","unstructured":"Heiderich M, Sp\u00e4th C, Schwenk J (2017) Dompurify: Client-side protection against XSS and markup injection. In: Foley SN, Gollmann D, Snekkenes E (eds) Computer Security - ESORICS 2017. Springer International Publishing, Cham, pp 116\u2013134"},{"key":"10323_CR15","doi-asserted-by":"publisher","unstructured":"Jim T, Swamy N, Hicks M (2007) Defeating script injection attacks with browser-enforced embedded policies. In: Proceedings of the 16th International Conference on World Wide Web. ACM, New York, NY, USA, WWW \u201907, pp 601\u2013610. https:\/\/doi.org\/10.1145\/1242572.1242654","DOI":"10.1145\/1242572.1242654"},{"key":"10323_CR16","doi-asserted-by":"publisher","unstructured":"Kieyzun A, Guo PJ, Jayaraman K, et\u00a0al (2009) Automatic creation of sql injection and cross-site scripting attacks. In: 2009 IEEE 31st International Conference on Software Engineering. pp 199\u2013209. https:\/\/doi.org\/10.1109\/ICSE.2009.5070521","DOI":"10.1109\/ICSE.2009.5070521"},{"issue":"7","key":"10323_CR17","doi-asserted-by":"publisher","first-page":"592","DOI":"10.1016\/j.cose.2009.04.008","volume":"28","author":"E Kirda","year":"2009","unstructured":"Kirda E, Jovanovic N, Kruegel C et al (2009) Client-side cross-site scripting protection. Comput Secur 28(7):592\u2013604. https:\/\/doi.org\/10.1016\/j.cose.2009.04.008","journal-title":"Client-side cross-site scripting protection. Comput Secur"},{"key":"10323_CR18","doi-asserted-by":"crossref","unstructured":"Kocher P, Genkin D, Gruss D, et\u00a0al (2018) Spectre attacks: Exploiting speculative execution. CoRR arXiv:1801.01203","DOI":"10.1109\/SP.2019.00002"},{"key":"10323_CR19","unstructured":"Moz (2022) Moz top 500 websites. https:\/\/moz.com\/top500"},{"key":"10323_CR20","unstructured":"Nadji Y, Saxena P, Song D (2009) Document structure integrity: A robust basis for cross-site scripting defense. In: NDSS"},{"key":"10323_CR21","unstructured":"nav (2019) Navigation timing level 2. https:\/\/www.w3.org\/TR\/navigation-timing-2\/"},{"key":"10323_CR22","doi-asserted-by":"crossref","unstructured":"Nguyen-Tuong A, Guarnieri S, Greene D et al (2005) Automatically hardening web applications using precise tainting. Security and Privacy in the Age of Ubiquitous Computing, IFIP TC11 20th International Conference on Information Security (SEC 2005), May 30 - June 1, 2005. Chiba, Japan, pp 295\u2013308","DOI":"10.1007\/0-387-25660-1_20"},{"key":"10323_CR23","unstructured":"nMa (2019) nmap network mapper. https:\/\/nmap.org\/"},{"key":"10323_CR24","unstructured":"Noscript (2022) Noscript homepage. https:\/\/noscript.net\/"},{"key":"10323_CR25","doi-asserted-by":"publisher","unstructured":"Pan J, Mao X (2017) Detecting dom-sourced cross-site scripting in browser extensions. In: 2017 IEEE International Conference on Software Maintenance and Evolution (ICSME). pp 24\u201334. https:\/\/doi.org\/10.1109\/ICSME.2017.11","DOI":"10.1109\/ICSME.2017.11"},{"key":"10323_CR26","doi-asserted-by":"publisher","unstructured":"Pazos JC, L\u00e9gar\u00e9 JS, Beschastnikh I (2021) Xsnare: Application-specific client-side cross-site scripting protection. In: 2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). pp 154\u2013165. https:\/\/doi.org\/10.1109\/SANER50967.2021.00023","DOI":"10.1109\/SANER50967.2021.00023"},{"key":"10323_CR27","doi-asserted-by":"publisher","unstructured":"Pietraszek T, Berghe CV (2006) Defending against injection attacks through context-sensitive string evaluation. In: Proceedings of the 8th International Conference on Recent Advances in Intrusion Detection. Springer-Verlag, Berlin, Heidelberg, RAID\u201905. pp 124\u2013145. https:\/\/doi.org\/10.1007\/11663812_7","DOI":"10.1007\/11663812_7"},{"key":"10323_CR28","unstructured":"Rap (2018) Security report for in-production web applications. https:\/\/www.rapid7.com\/resources\/security-report-for-in-production-web-applications\/"},{"key":"10323_CR29","unstructured":"Rap (2021) The 2021 vulnerability intelligence report. https:\/\/www.rapid7.com\/products\/insightvm\/vulnerability-report-hub-page\/"},{"key":"10323_CR30","unstructured":"rcc (2019) Responsive cookie consent 1.8 patches. https:\/\/plugins.trac.wordpress.org\/browser\/responsive-cookie-consent\/tags\/1.8\/includes\/admin-page.php"},{"key":"10323_CR31","unstructured":"saf (2019) Safely inserting external content into a page. https:\/\/developer.mozilla.org\/en-US\/docs\/Mozilla\/Add-ons\/WebExtensions\/Safely_inserting_external_content_into_a_page"},{"key":"10323_CR32","doi-asserted-by":"publisher","unstructured":"Snyder P, Taylor C, Kanich C (2017) Most websites don\u2019t need to vibrate: A cost-benefit approach to improving browser security. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, New York, NY, USA, CCS \u201917. pp 179\u2013194. https:\/\/doi.org\/10.1145\/3133956.3133966","DOI":"10.1145\/3133956.3133966"},{"key":"10323_CR33","doi-asserted-by":"crossref","unstructured":"Steffens M, Rossow C, Johns M, et\u00a0al (2019) Don\u2019t trust the locals: Investigating the prevalence of persistent client-side cross-site scripting in the wild. In: 26th Annual Network and Distributed System Security Symposium, NDSS 2019, San Diego, California, USA, February 24-27, 2019","DOI":"10.14722\/ndss.2019.23009"},{"key":"10323_CR34","unstructured":"Stock B, Johns M, Steffens M, et\u00a0al (2017) How the web tangled itself: Uncovering the history of client-side web (in)security. In: Proceedings of the 26th USENIX Conference on Security Symposium. USENIX Association, Berkeley, CA, USA, SEC\u201917, pp 971\u2013987. http:\/\/dl.acm.org\/citation.cfm?id=3241189.3241265"},{"key":"10323_CR35","unstructured":"Stock B, Lekies S, Mueller T, et\u00a0al (2014) Precise client-side protection against dom-based cross-site scripting. In: Proceedings of the 23rd USENIX Conference on Security Symposium. USENIX Association, Berkeley, CA, USA, SEC\u201914. pp 655\u2013670. http:\/\/dl.acm.org\/citation.cfm?id=2671225.2671267"},{"key":"10323_CR36","unstructured":"stu (2019) Wordpress plugin responsive cookie consent 1.7 \/ 1.6 \/ 1.5 - (authenticated) persistent cross-site scripting. https:\/\/www.exploit-db.com\/exploits\/44563"},{"key":"10323_CR37","unstructured":"Suc (2021) 2021 website threat research report. https:\/\/sucuri.net\/wp-content\/uploads\/2022\/04\/sucuri-2021-hacked-report.pdf"},{"key":"10323_CR38","doi-asserted-by":"publisher","unstructured":"Sundareswaran S, Squicciarini AC (2012) XSS-Dec: A hybrid solution to mitigate cross-site scripting attacks. In: Proceedings of the 26th Annual IFIP WG 11.3 Conference on Data and Applications Security and Privacy. Springer-Verlag, Berlin, Heidelberg, DBSec\u201912. pp 223\u2013238. https:\/\/doi.org\/10.1007\/978-3-642-31540-4_17","DOI":"10.1007\/978-3-642-31540-4_17"},{"key":"10323_CR39","doi-asserted-by":"crossref","unstructured":"Sun F, Xu L, Su Z (2009) Client-side detection of XSS worms by monitoring payload propagation. In: Backes M, Ning P (eds) Computer Security - ESORICS 2009. Springer Berlin Heidelberg, Berlin, Heidelberg, pp 539\u2013554","DOI":"10.1007\/978-3-642-04444-1_33"},{"key":"10323_CR40","unstructured":"uBlockOrigin (2022) ublock origin. https:\/\/github.com\/gorhill\/uBlock#ublock-origin"},{"key":"10323_CR41","unstructured":"w3s (2019) Usage of content management systems for websites. https:\/\/w3techs.com\/technologies\/overview\/content_management\/all"},{"key":"10323_CR42","doi-asserted-by":"publisher","unstructured":"Wassermann G, Su Z (2008) Static detection of cross-site scripting vulnerabilities. In: Proceedings of the 30th International Conference on Software Engineering. Association for Computing Machinery, New York, NY, USA, ICSE \u201908. p 171-180. https:\/\/doi.org\/10.1145\/1368088.1368112","DOI":"10.1145\/1368088.1368112"},{"key":"10323_CR43","doi-asserted-by":"publisher","unstructured":"Wassermann G, Yu D, Chander A, et\u00a0al (2008) Dynamic test input generation for web applications. In: Proceedings of the 2008 International Symposium on Software Testing and Analysis. Association for Computing Machinery, New York, NY, USA, ISSTA \u201908. p 249-260. https:\/\/doi.org\/10.1145\/1390630.1390661","DOI":"10.1145\/1390630.1390661"},{"key":"10323_CR44","unstructured":"wpp (2019) Wordpress: Plugins. https:\/\/wordpress.org\/plugins\/"},{"key":"10323_CR45","unstructured":"wps (2019) Wpscan. https:\/\/wpscan.org\/"},{"key":"10323_CR46","unstructured":"wpw (2019) Statistics show why wordpress is a popular hacker target. https:\/\/www.wpwhitesecurity.com\/statistics-70-percent-wordpress-installations-vulnerable\/"},{"key":"10323_CR47","doi-asserted-by":"publisher","unstructured":"Wurzinger P, Platzer C, Ludl C, et\u00a0al (2009) Swap: Mitigating XSS attacks using a reverse proxy. In: Proceedings of the 2009 ICSE Workshop on Software Engineering for Secure Systems. IEEE Computer Society, Washington, DC, USA, IWSESS \u201909. pp 33\u201339. https:\/\/doi.org\/10.1109\/IWSESS.2009.5068456","DOI":"10.1109\/IWSESS.2009.5068456"},{"key":"10323_CR48","doi-asserted-by":"publisher","unstructured":"Xiao X, Paradkar A, Thummalapenta S, et\u00a0al (2012) Automated extraction of security policies from natural-language software documents. In: Proceedings of the ACM SIGSOFT 20th International Symposium on the Foundations of Software Engineering. Association for Computing Machinery, New York, NY, USA, FSE \u201912. https:\/\/doi.org\/10.1145\/2393596.2393608","DOI":"10.1145\/2393596.2393608"},{"key":"10323_CR49","unstructured":"xss (2019) XSS auditor. https:\/\/www.chromium.org\/developers\/design-documents\/xss-auditor"},{"key":"10323_CR50","unstructured":"xss (2020) Cve details vulnerabilities by type. https:\/\/www.cvedetails.com\/vulnerabilities-by-types.php"},{"key":"10323_CR51","unstructured":"Xu W, Bhatkar S, Sekar R (2006) Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In: Proceedings of the 15th Conference on USENIX Security Symposium - Volume 15. USENIX Association, Berkeley, CA, USA, USENIX-SS\u201906. http:\/\/dl.acm.org\/citation.cfm?id=1267336.1267345"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-023-10323-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-023-10323-w\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-023-10323-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,4]],"date-time":"2023-10-04T12:17:16Z","timestamp":1696421836000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-023-10323-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,17]]},"references-count":51,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2023,9]]}},"alternative-id":["10323"],"URL":"https:\/\/doi.org\/10.1007\/s10664-023-10323-w","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,8,17]]},"assertion":[{"value":"15 March 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 August 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The three authors do not have any conflicts of interest with regard to this publication. This research did not involve any human participants.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with Ethical Standards"}}],"article-number":"110"}}