TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

We Built a Protection Against DOM-Based Cross-Site Scripting into Chromium

26 点作者 cujanovic大约 9 年前

2 条评论

ubernostrum大约 9 年前
I'd be interested to see a comparison between this and the measures Microsoft has been building in since IE8. IIRC Microsoft avoided full taint checking of strings and went with an approach of just looking for reflected content.
评论 #11236387 未加载
xyzzy123大约 9 年前
So, an up-to-date DOMinator for Chrome but with no source code available?<p>I quite liked the discussion of issues with current XSS auditor in Chrome although I felt it was pressing the point a bit to call it &quot;state of the art&quot;.
评论 #11236573 未加载