Lightweight, embedded Web servers are soon about to outnumber regular Internet Web servers. They reside in devices entrusted with personal and corporate data, and are typically used for configuration and management. We reveal a series of attacks on consumer and small office electronics, ranging from networked storage to digital photo frames. The attacks target Web server logic and are based on a new type of vulnerability that we call cross channel scripting (XCS). XCS is a sophisticated form of cross site scripting (XSS) in which the attack injection and execution are carried out via different protocols.
The emergence of cross channel scripting
| Available Media | |
|---|---|
| Conference | Communications of the ACM Journal (CACM) - 2010 |
| Authors | Hristo Bojinov , Elie Bursztein , Dan Boneh |
| Citation | BibTeX |
Recent
ai
Facade: High-Precision Insider Threat Detection Using Deep Contextual Anomaly Detection
publications
Usenix Security 2026
ai
ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?
publications
NeurIPS 2026
Cybersecurity
DROIDCCT: Cryptographic Compliance Test via Trillion-Scale Measurement
publications
ACSAC 2025