Mario Heiderich, profile picture

Mario Heiderich

Sort by
An Abusive Relationship with AngularJS
Copy & Pest - A case-study on the clipboard, blind trust and invisible cross-application XSS
ECMAScript 6 from an Attacker's Perspective - Breaking Frameworks, Sandboxes, and everything else
In the DOM, no one will hear you scream
JSMVCOMFG - To sternly look at JavaScript MVC and Templating Frameworks
The innerHTML Apocalypse
Scriptless Attacks - Stealing the Pie without touching the Sill
Locking the Throneroom 2.0
The Image that called me - Active Content Injection with SVG Files
Locking the Throne Room - How ES5+ might change views on XSS and Client Side Security
Dev and Blind - Attacking the weakest Link in IT Security
HTML5 - The Good, the Bad, the Ugly
I thought you were my friend - Malicious Markup
The Future of Web Attacks - CONFidence 2010
Web Wuermer