xJS: practical XSS prevention for web application development
Elias Athanasopoulos, Vasilis Pappas, Antonis Krithinakis, Spyros Ligouras, Evangelos P. Markatos, Thomas Karagiannis · 2010
We present xJS, a practical framework for preventing code-injections in the web environment and thus assisting for the development of XSS-free web applications. xJS aims on being fast, developer-friendly and providing backwards compatibility. We implement and evaluate our solution in three leading web browsers and in the Apache web server. We show that our framework can successfully prevent all 1,380 real-world attacks that were collected from a wellknown XSS attack repository. Furthermore, our framework imposes negligible computational overhead in both the server and the client side, and has no negative sideeffects in the overall user’s browsing experience. 1