{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T13:19:51Z","timestamp":1773235191067,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":21,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,4,1]],"date-time":"2008-04-01T00:00:00Z","timestamp":1207008000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,4]]},"DOI":"10.1145\/1435497.1435502","type":"proceedings-article","created":{"date-parts":[[2008,10,14]],"date-time":"2008-10-14T17:49:52Z","timestamp":1224006592000},"page":"25-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Talking to strangers without taking their candy"],"prefix":"10.1145","author":[{"given":"Adrienne","family":"Felt","sequence":"first","affiliation":[{"name":"University of Virginia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pieter","family":"Hooimeijer","sequence":"additional","affiliation":[{"name":"University of Virginia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Evans","sequence":"additional","affiliation":[{"name":"University of Virginia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Westley","family":"Weimer","sequence":"additional","affiliation":[{"name":"University of Virginia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"M. Broersma. Cross-site scripting the top security risk. Technical report http:\/\/www.networkworld.com\/news\/2006\/091806-cross-site-scripting-the -top-security.html Sep 2006.  M. Broersma. Cross-site scripting the top security risk. Technical report http:\/\/www.networkworld.com\/news\/2006\/091806-cross-site-scripting-the -top-security.html Sep 2006."},{"key":"e_1_3_2_1_2_1","unstructured":"D. Crockford. The module Tag. Technical report http:\/\/www.json.org\/module.html Oct 2006.  D. Crockford. The module Tag. Technical report http:\/\/www.json.org\/module.html Oct 2006."},{"key":"e_1_3_2_1_3_1","volume-title":"Identifying Cross Site Scripting Vulnerabilities in Web Applications. In","author":"DiLucca G. A.","year":"2004","unstructured":"G. A. DiLucca , A. R. Fasolino , M. Mastoianni , and w P. Tramontana . Identifying Cross Site Scripting Vulnerabilities in Web Applications. In , 2004 . G. A. DiLucca, A. R. Fasolino, M. Mastoianni, and wP. Tramontana. Identifying Cross Site Scripting Vulnerabilities in Web Applications. In, 2004."},{"key":"e_1_3_2_1_4_1","unstructured":"B. Eich. JavaScript: Mobility and Ubiquity. Technical report http:\/\/kathrin.dagstuhl.de\/files\/Materials\/07\/07091\/07091.EichBrendan.Slides.pdf Sep 2007.  B. Eich. JavaScript: Mobility and Ubiquity. Technical report http:\/\/kathrin.dagstuhl.de\/files\/Materials\/07\/07091\/07091.EichBrendan.Slides.pdf Sep 2007."},{"key":"e_1_3_2_1_5_1","unstructured":"EveryBlock Incorporated. EveryBlock. http:\/\/chicago.everyblock.com\/.  EveryBlock Incorporated. EveryBlock . http:\/\/chicago.everyblock.com\/."},{"key":"e_1_3_2_1_6_1","unstructured":"Facebook. Facebook Application Directory. http:\/\/uva.facebook.com\/apps\/.  Facebook. Facebook Application Directory . http:\/\/uva.facebook.com\/apps\/."},{"key":"e_1_3_2_1_7_1","unstructured":"Facebook. Facebook Platform Developer Guide. http:\/\/developers.facebook.com\/.  Facebook. Facebook Platform Developer Guide . http:\/\/developers.facebook.com\/."},{"key":"e_1_3_2_1_8_1","unstructured":"A. Felt. The Facebook Chronicles. Technical report http:\/\/www.cs.virginia.edu\/felt\/fbook\/ Aug 2007.  A. Felt. The Facebook Chronicles. Technical report http:\/\/www.cs.virginia.edu\/felt\/fbook\/ Aug 2007."},{"key":"e_1_3_2_1_9_1","unstructured":"Flickr. Create your own Flickr badge. http:\/\/www.flickr.com\/badge.gne.  Flickr. Create your own Flickr badge . http:\/\/www.flickr.com\/badge.gne."},{"key":"e_1_3_2_1_10_1","unstructured":"Google. What is the Google Maps API? http:\/\/code.google.com\/apis\/maps\/.  Google. What is the Google Maps API? http:\/\/code.google.com\/apis\/maps\/."},{"key":"e_1_3_2_1_11_1","unstructured":"Google. Google Launches OpenSocial to Spread Social Applications Across The Web. Technical report http:\/\/www.google.com\/intl\/en\/press\/pressrel\/opensocial.html Nov 2007.  Google. Google Launches OpenSocial to Spread Social Applications Across The Web. Technical report http:\/\/www.google.com\/intl\/en\/press\/pressrel\/opensocial.html Nov 2007."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/988672.988679"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242654"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.29"},{"key":"e_1_3_2_1_15_1","unstructured":"Microsoft. SECURITY Attribute (FRAME IFRAME). Technical report http:\/\/msdn2.microsoft.com\/en-us\/library\/ms534622(VS.85).aspx.  Microsoft. SECURITY Attribute (FRAME IFRAME). Technical report http:\/\/msdn2.microsoft.com\/en-us\/library\/ms534622(VS.85).aspx."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the 7th Symposium on Operating Systems Design and Implementation","author":"Reis C.","year":"2006","unstructured":"C. Reis , J. Dunagan , H. J. Wang , O. Dubrovsky , and S. Esmeir . BrowserShield: Vulnerability-driven filtering of dynamic HTML . In Proceedings of the 7th Symposium on Operating Systems Design and Implementation , 2006 . C. Reis, J. Dunagan, H. J. Wang, O. Dubrovsky, and S. Esmeir. BrowserShield: Vulnerability-driven filtering of dynamic HTML. In Proceedings of the 7th Symposium on Operating Systems Design and Implementation, 2006."},{"key":"e_1_3_2_1_17_1","unstructured":"Samy. Technical explanation of The MySpace Worm. Technical report http:\/\/namb.la\/popular\/tech.html Oct 2005.  Samy. Technical explanation of The MySpace Worm. Technical report http:\/\/namb.la\/popular\/tech.html Oct 2005."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the 14th Annual Network and Distributed System Security Conference","author":"Vogt P.","year":"2007","unstructured":"P. Vogt , F. Nentwich , N. Jovanovic , E. Kirda , C. Kruegel , and G. Vigna . Cross Site Scripting Prevention with Dynamic Data Tainting and Static Analysis . In Proceedings of the 14th Annual Network and Distributed System Security Conference , 2007 . P. Vogt, F. Nentwich, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Cross Site Scripting Prevention with Dynamic Data Tainting and Static Analysis. In Proceedings of the 14th Annual Network and Distributed System Security Conference, 2007."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1294261.1294263"},{"key":"e_1_3_2_1_20_1","unstructured":"Yahoo! ADsafe. http:\/\/adsafe.org.  Yahoo! ADsafe . http:\/\/adsafe.org."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1190216.1190252"}],"event":{"name":"Eurosys '08: Eurosys 2008 Conference","location":"Glasgow Scotland","acronym":"Eurosys '08","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 1st Workshop on Social Network Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1435497.1435502","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1435497.1435502","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T12:45:51Z","timestamp":1750250751000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1435497.1435502"}},"subtitle":["isolating proxied content"],"short-title":[],"issued":{"date-parts":[[2008,4]]},"references-count":21,"alternative-id":["10.1145\/1435497.1435502","10.1145\/1435497"],"URL":"https:\/\/doi.org\/10.1145\/1435497.1435502","relation":{},"subject":[],"published":{"date-parts":[[2008,4]]},"assertion":[{"value":"2008-04-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}