Capability of Security Scanners:
| dc.contributor.author | Antonsson, Philip | |
| dc.contributor.author | Carlson, Vincent | |
| dc.contributor.department | Chalmers tekniska högskola / Institutionen för data och informationsteknik | sv |
| dc.contributor.department | Chalmers University of Technology / Department of Computer Science and Engineering | en |
| dc.contributor.examiner | Duvignau, Romaric | |
| dc.contributor.supervisor | Picazo-Sanchez, Pablo | |
| dc.date.accessioned | 2025-09-10T11:28:30Z | |
| dc.date.issued | 2024 | |
| dc.date.submitted | ||
| dc.description.abstract | Cross-site scripting is one of the biggest threats for websites and their users, and with the ever evolving technologies it can be hard for developers and users to know if they are vulnerable to cross-site scripting. In the last couple of years, server-side rendered frameworks have grown in popularity, though how vulnerable this technology is to cross-site scripting is not entirely clear. In this thesis, we evaluate how vulnerability scanners preform on different frameworks used in web development. As well as highlight what shortcomings they have along with potential problems this poses. We found that Remix especially does not have the support from the current tools that it needs, as Remix has server-side rendering, credence can then be put towards the speculation that it needs further focus. To mitigate this we propose an extension which extends CodeQL with custom queries to better suit the shortcomings we identified. | |
| dc.identifier.coursecode | DATX05 | |
| dc.identifier.uri | http://hdl.handle.net/20.500.12380/310448 | |
| dc.language.iso | eng | |
| dc.relation.ispartofseries | CSE 24-173 | |
| dc.setspec.uppsok | Technology | |
| dc.subject | CodeQL, Cross-Site Scripting, React, Remix, TypeScript, Vulnerability Scanning, Web-Development. | |
| dc.title | Capability of Security Scanners: | |
| dc.type.degree | Examensarbete för masterexamen | sv |
| dc.type.degree | Master's Thesis | en |
| dc.type.uppsok | H | |
| local.programme | Computer systems and networks (MPCSN), MSc |
