No boundaries: data exfiltration by third parties embedded on web pages

We investigate data exfiltration by third-party scripts directly embedded on web pages. Specifically, we study three attacks: misuse of browsers’ internal login managers, social data exfiltration, and whole-DOM exfiltration. Although the possibility of these attacks was well known, we provide the fi...

Full description

Bibliographic Details
Main Authors: Acar Gunes, Englehardt Steven, Narayanan Arvind
Format: Article
Language:English
Published: Sciendo 2020-10-01
Series:Proceedings on Privacy Enhancing Technologies
Subjects:
Online Access:https://doi.org/10.2478/popets-2020-0070