Capability of Security Scanners:

dc.contributor.authorAntonsson, Philip
dc.contributor.authorCarlson, Vincent
dc.contributor.departmentChalmers tekniska högskola / Institutionen för data och informationstekniksv
dc.contributor.departmentChalmers University of Technology / Department of Computer Science and Engineeringen
dc.contributor.examinerDuvignau, Romaric
dc.contributor.supervisorPicazo-Sanchez, Pablo
dc.date.accessioned2025-09-10T11:28:30Z
dc.date.issued2024
dc.date.submitted
dc.description.abstractCross-site scripting is one of the biggest threats for websites and their users, and with the ever evolving technologies it can be hard for developers and users to know if they are vulnerable to cross-site scripting. In the last couple of years, server-side rendered frameworks have grown in popularity, though how vulnerable this technology is to cross-site scripting is not entirely clear. In this thesis, we evaluate how vulnerability scanners preform on different frameworks used in web development. As well as highlight what shortcomings they have along with potential problems this poses. We found that Remix especially does not have the support from the current tools that it needs, as Remix has server-side rendering, credence can then be put towards the speculation that it needs further focus. To mitigate this we propose an extension which extends CodeQL with custom queries to better suit the shortcomings we identified.
dc.identifier.coursecodeDATX05
dc.identifier.urihttp://hdl.handle.net/20.500.12380/310448
dc.language.isoeng
dc.relation.ispartofseriesCSE 24-173
dc.setspec.uppsokTechnology
dc.subjectCodeQL, Cross-Site Scripting, React, Remix, TypeScript, Vulnerability Scanning, Web-Development.
dc.titleCapability of Security Scanners:
dc.type.degreeExamensarbete för masterexamensv
dc.type.degreeMaster's Thesisen
dc.type.uppsokH
local.programmeComputer systems and networks (MPCSN), MSc

Ladda ner

Original bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
CSE 24-173 PA VC.pdf
Storlek:
8.46 MB
Format:
Adobe Portable Document Format

License bundle

Visar 1 - 1 av 1
Hämtar...
Bild (thumbnail)
Namn:
license.txt
Storlek:
2.35 KB
Format:
Item-specific license agreed upon to submission
Beskrivning: