User Input Piercing for Cross-Site Scripting Attacks
OWASP AppSec DC 2009
http://www.owasp.org/index.php/OWASP_AppSec_DC_200
Abstract:
This paper presents algorithms and techniques for performing user input piercing on a web application. We also introduce a heuristic to determine if a given cross-site scripting attack will effectively execute scripting code on the compromised browser. In addition, an algorithm to detect the need of encoding techniques is presented.











