Re: [Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread Stefano Di Paola
Hey IEhrepus Il giorno mer, 18/05/2011 alle 20.34 -0700, IEhrepus ha scritto: > > DOMinator can't work on firefox 3.6.17? DOMinator consists in a core and an extension. The core is Firefox with some custom c/c++ code in order to add taint flag to JSStrings and deal with taint propagation. So,

Re: [Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread IEhrepus
hi DOMinator can't work on firefox 3.6.17? hitest 2011/5/18 Stefano Di Paola > What is DOMinator? > DOMinator is a Firefox based software for analysis and identification of > DOM Based Cross Site Scripting issues (DOMXss). > It is the first runtime tool which can help security testers to ide

[Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread Stefano Di Paola
What is DOMinator? DOMinator is a Firefox based software for analysis and identification of DOM Based Cross Site Scripting issues (DOMXss). It is the first runtime tool which can help security testers to identify DOMXss. How it works? It uses dynamic runtime tainting model on strings and can trac