The Hidden Cost Of Sanitization How Secure Parsing Can Introduce New Xss Attack Surfaces
About this talk
This talk covers the complexities of modern sanitization pipelines, which are evolving from mere content filtering to active transformation, introducing potential risks. Ashish Kataria, a security architect engineer at Synacor, discusses how issues like namespace confusion, token merging, and serialization side effects can create exploitable gaps within these pipelines. He also explains how multi-stage sanitizers and regex-based rewrites can inadvertently generate cross-site scripting (XSS) attack surfaces. The session further delves into methodologies for auditing vulnerabilities induced by sanitizers, utilizing techniques such as DOM comparison, structural mutation testing, and browser-consistent parsing models.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56