Browser Web Storage Vulnerability Investigation: HTML5 localStorage Object
نویسندگان
چکیده
Along with the introduction of HTML5 a new data storage technique, Web Storage, has been added to browsers. This technique stores larger amounts of data for an extended period of time on a client system. This technology does not (as of this writing) have a fully implemented interface to support end user control. The authors interest is modeling the use of Web Storage to store illicit data. The authors built a web application that would take a file, encrypt it, split it into multiple parts and distribute it to as many clients as possible. At a later time, the system could then watch for return visits and retrieve data parts as clients interact with a host website. The recidivism rate of clients returning to the host website and the number of copies of each distributed part needed to achieve a reliable recovery rate of the entire file are under study.
منابع مشابه
An investigation into possible attacks on HTML5 IndexedDB and their prevention
over the past 20 years web browsers have changed considerably from being a simple text display to now supporting complex multimedia applications [1]. The client can now enjoy chatting, playing games and Internet banking. All these applications have something in common, they can be run on multiple platforms and in some cases they will run offline. With the introduction of HTML5 this evolution wi...
متن کاملElastic HTML5: Workload Offloading Using Cloud-Based Web Workers and Storages for Mobile Devices
In this position paper, we propose the concept of Elastic HTML5, which enables web applications to offload workload using cloudbased web workers and cloud-based storage for mobile devices. Elastic HTML5 is a collection of software components and functions in for a web runtime agent (e.g., web browser); this includes components and methods to create and manage web workers in the cloud so as to a...
متن کاملIdentifying Cross-origin Resource Status Using Application Cache
HTML5 Application Cache (AppCache) allows web applications to cache their sameand cross-origin resources in the local storage of a web browser to enable offline access. However, cross-origin resource caching in AppCache has potential security and privacy problems. In this paper, we consider a novel web privacy attack that exploits cross-origin AppCache. Our attack allows a remote web attacker t...
متن کاملReconstructing and Visualizing Evidence of Artifact from Firefox SessionStorage
Importance of digital forensics is expected to increase in the future.Many of researches on digital forensics are targeted to persistent memory. These researches concerns about the extraction of evidence directly or via filesystem. On the other hand, there is a movement to employ the Web browser supports HTML5 as software platform. In this situation, it is considered that the forensics techniqu...
متن کاملVulnerability of Web-Storage in HTML5 for Web and Mobile Application
HTML5 is not a new version of the existing markup language, but a new paradigm for developing web and mobile applications where various new concepts are introduced to improve compatibility and usability. Web-Storage is the one of new features in HTML5 that enables effective client-side storage and retrieval of the frequently used data. However, it has significant security problems which need to...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016