Matches in SemOpenAlex for { <https://semopenalex.org/work/W2524526547> ?p ?o ?g. }
Showing items 1 to 96 of
96
with 100 items per page.
- W2524526547 abstract "With the constant migration of applications from the desktop to the web, power users have found ways of enhancing web applications, at the client-side, according to their needs. In this paper, we investigate this phenomenon by focusing on the popular Greasemonkey extension which enables users to write scripts that arbitrarily change the content of any page, allowing them to remove unwanted features from web applications, or add additional, desired features to them. The creation of script markets, on which these scripts are often shared, extends the standard web security model with two new actors, introducing newly identified types of vulnerabilities. We describe the architecture of Greasemonkey and perform a large-scale analysis of the most popular, community-driven, script market for Greasemonkey. Through our analysis, we discover not only dozens of malicious scripts waiting to be installed by users, but thousands of benign scripts with vulnerabilities that could be abused by attackers. In 58 cases, the vulnerabilities are so severe, that they can be used to bypass the Same-Origin Policy of the user’s browser and steal sensitive user-data from all sites. We have discovered several of these severely vulnerable scripts, with over a million installations, and created a proof-of-concept exploit that successfully launches a novel “Man-in-the-browser” attack against an installed vulnerable script with an installation base of 1.2" @default.
- W2524526547 created "2016-10-07" @default.
- W2524526547 creator A5008329832 @default.
- W2524526547 creator A5014031812 @default.
- W2524526547 creator A5054031138 @default.
- W2524526547 creator A5054273170 @default.
- W2524526547 creator A5081256404 @default.
- W2524526547 date "2014-03-01" @default.
- W2524526547 modified "2023-09-25" @default.
- W2524526547 title "Monkey-in-the-browser: Malware and vulnerabilities in augmented browsing script markets -- extended version" @default.
- W2524526547 cites W1519699895 @default.
- W2524526547 cites W1520941164 @default.
- W2524526547 cites W1525967479 @default.
- W2524526547 cites W1598325486 @default.
- W2524526547 cites W1753538339 @default.
- W2524526547 cites W1849635621 @default.
- W2524526547 cites W1887482550 @default.
- W2524526547 cites W1970867218 @default.
- W2524526547 cites W1987644478 @default.
- W2524526547 cites W2039999720 @default.
- W2524526547 cites W2083785453 @default.
- W2524526547 cites W2095450067 @default.
- W2524526547 cites W2111165162 @default.
- W2524526547 cites W2160289821 @default.
- W2524526547 cites W2169771430 @default.
- W2524526547 cites W2404981861 @default.
- W2524526547 cites W36927914 @default.
- W2524526547 cites W58852127 @default.
- W2524526547 hasPublicationYear "2014" @default.
- W2524526547 type Work @default.
- W2524526547 sameAs 2524526547 @default.
- W2524526547 citedByCount "1" @default.
- W2524526547 countsByYear W25245265472015 @default.
- W2524526547 crossrefType "journal-article" @default.
- W2524526547 hasAuthorship W2524526547A5008329832 @default.
- W2524526547 hasAuthorship W2524526547A5014031812 @default.
- W2524526547 hasAuthorship W2524526547A5054031138 @default.
- W2524526547 hasAuthorship W2524526547A5054273170 @default.
- W2524526547 hasAuthorship W2524526547A5081256404 @default.
- W2524526547 hasConcept C111919701 @default.
- W2524526547 hasConcept C118643609 @default.
- W2524526547 hasConcept C127613066 @default.
- W2524526547 hasConcept C136764020 @default.
- W2524526547 hasConcept C165696696 @default.
- W2524526547 hasConcept C195274430 @default.
- W2524526547 hasConcept C21959979 @default.
- W2524526547 hasConcept C38652104 @default.
- W2524526547 hasConcept C39569185 @default.
- W2524526547 hasConcept C41008148 @default.
- W2524526547 hasConcept C541664917 @default.
- W2524526547 hasConcept C59241245 @default.
- W2524526547 hasConcept C61096286 @default.
- W2524526547 hasConcept C61423126 @default.
- W2524526547 hasConcept C79373723 @default.
- W2524526547 hasConceptScore W2524526547C111919701 @default.
- W2524526547 hasConceptScore W2524526547C118643609 @default.
- W2524526547 hasConceptScore W2524526547C127613066 @default.
- W2524526547 hasConceptScore W2524526547C136764020 @default.
- W2524526547 hasConceptScore W2524526547C165696696 @default.
- W2524526547 hasConceptScore W2524526547C195274430 @default.
- W2524526547 hasConceptScore W2524526547C21959979 @default.
- W2524526547 hasConceptScore W2524526547C38652104 @default.
- W2524526547 hasConceptScore W2524526547C39569185 @default.
- W2524526547 hasConceptScore W2524526547C41008148 @default.
- W2524526547 hasConceptScore W2524526547C541664917 @default.
- W2524526547 hasConceptScore W2524526547C59241245 @default.
- W2524526547 hasConceptScore W2524526547C61096286 @default.
- W2524526547 hasConceptScore W2524526547C61423126 @default.
- W2524526547 hasConceptScore W2524526547C79373723 @default.
- W2524526547 hasLocation W25245265471 @default.
- W2524526547 hasOpenAccess W2524526547 @default.
- W2524526547 hasPrimaryLocation W25245265471 @default.
- W2524526547 hasRelatedWork W105048401 @default.
- W2524526547 hasRelatedWork W1503745153 @default.
- W2524526547 hasRelatedWork W1630762513 @default.
- W2524526547 hasRelatedWork W1967374770 @default.
- W2524526547 hasRelatedWork W1983343365 @default.
- W2524526547 hasRelatedWork W2069054745 @default.
- W2524526547 hasRelatedWork W2125633495 @default.
- W2524526547 hasRelatedWork W2126709396 @default.
- W2524526547 hasRelatedWork W2133113868 @default.
- W2524526547 hasRelatedWork W2168563136 @default.
- W2524526547 hasRelatedWork W2185666069 @default.
- W2524526547 hasRelatedWork W2244817461 @default.
- W2524526547 hasRelatedWork W2523390657 @default.
- W2524526547 hasRelatedWork W2767115056 @default.
- W2524526547 hasRelatedWork W2893936826 @default.
- W2524526547 hasRelatedWork W2908401980 @default.
- W2524526547 hasRelatedWork W3098243143 @default.
- W2524526547 hasRelatedWork W3163114011 @default.
- W2524526547 hasRelatedWork W178807294 @default.
- W2524526547 hasRelatedWork W1918499692 @default.
- W2524526547 isParatext "false" @default.
- W2524526547 isRetracted "false" @default.
- W2524526547 magId "2524526547" @default.
- W2524526547 workType "article" @default.