Research Papers on HTML5 Security

Academic research and in-depth technical analyses

↑ Top

A Security Analysis of Next Generation Web Standards

↓ Download

The Emperor’s New APIs: On the (In)Secure Usage of New Client-side Primitives

↓ Download

HTML5 Overview: A Look at HTML5 Attack Scenarios

↓ Download

HTML5 Web Security

↓ Download

Attacking with HTML5

↓ Download

Abusing HTML 5 Structured Client-side Storage

↓ Download

Blog Posts on HTML5 Security

Community articles and technical write-ups

↑ Top

How a Platform Using HTML5 Can Affect the Security of Your Website

↗ View

Invisible arbitrary CSRF file upload in Flickr.com

↗ View

Minus.com silent arbitrary file upload

↗ View

Cross domain arbitrary file upload Redux

↗ View

How to upload arbitrary file contents cross-domain

↗ View

Filejacking: How to make a file server from your browser (with HTML5 of course)

↗ View

HTML5 WebSockets — security & new tool for attacking

↗ View

Squid-imposter: Phishing websites forever with HTML5 offline cache

↗ View

XSS track got ninja stealth skills thanks to HTML5

↗ View

XSS-Track now steals your uploaded files with HTML5 power!

↗ View

CSRF with JSON — leveraging XHR and CORS

↗ View

Blind WebSQL and Storage extraction for HTML5 Apps

↗ View

Top 10 HTML5 Threats & Attack Vectors

↗ View

Hacking Facebook with HTML5

↗ View

Cracking hashes in the JavaScript cloud with Ravan

↗ View

Performing DDoS attacks with HTML5 Cross Origin Requests & WebWorkers

↗ View

Port Scanning with HTML5 and JS-Recon

↗ View

Shell of the Future — Reverse Web Shell Handler for XSS Exploitation

↗ View

Chrome and Safari users open to stealth HTML5 AppCache attack

↗ View

HTML5 Security Articles and Live Demos

↗ View

Slides from Presentations on HTML5 Security

Conference and workshop presentation materials

↑ Top

HTML5 — The Good, the Bad, the Ugly

↓ Download

HTML5: something wicked this way comes — HackPra

↗ View

HTML5 Web Security

↓ Download

Web security in the frontend

↗ View

Abusing HTML5

↓ Download

HTML5 Advanced Computer Networks SS 2011

↓ Download

Pwning Intranets with HTML5

↓ Download

Can you trust your workers? Examining the security of Web Workers

↓ Download

Videos of Past Talks on HTML5 Security

Recorded presentations and conference sessions

↑ Top

HTML5 — The Good, the Bad, the Ugly (German)

↗ View

HTML5: something wicked this way comes

↗ View

Next Generation Web Attacks — HTML 5, DOM (L3) and XHR (L2)

↗ View

Attacking with HTML5

↗ View

Other Resources on HTML5 Security

Additional materials and community resources

↑ Top

Discussion on HTML5 Security at OWASP Summit 2011

↓ Download

HTML5 Security Cheatsheet Wiki

↗ View

HTML5 WebSQL and COR Security Demos

↗ View

Upcoming Talks on HTML5 Security

Scheduled presentations and conference appearances

↑ Top

HTML5 Top 10 Threats Stealth Attacks and Silent Exploits

BlackHat Europe 2012

↗ View