Publications
Code Reuse Attacks in PHP: Automated POP Chain Generation
2014 - Johannes Dahse, Nikolai Krein, Thorsten Holz
21st ACM Conference on Computer and Communications Security (CCS), Scottsdale, Arizona, USA, November 2014 - ** Best Student Paper Award ** [PDF]Static Detection of Second-Order Vulnerabilities in Web Applications
2014 - Johannes Dahse, Thorsten Holz
23rd USENIX Security Symposium, San Diego, CA, USA, August 2014 - ** Internet Defense Prize by Facebook ** [PDF]Simulation of Built-in PHP features for Precise Static Code Analysis
2014 - Johannes Dahse, Thorsten Holz
Annual Network & Distributed System Security Symposium (NDSS), San Diego, February 2014 [PDF]Crouching Tiger - Hidden Payload: Security Risks of Scalable Vectors Graphics
2011 - Mario Heiderich, Tilman Frosch, Meiko Jensen, Thorsten Holz
18th ACM Conference on Computer and Communications Security (CCS), Chicago, IL, October 2011 [PDF]IceShield: Detection and Mitigation of Malicious Websites with a Frozen DOM
2011 - Mario Heiderich, Tilman Frosch, Thorsten Holz
14th International Symposium on Recent Advances in Intrusion Detection (RAID), Menlo Park, CA, September 2011 [PDF]ADSandbox: Sandboxing JavaScript to Fight Malicious Websites
2010 - Andreas Dewald, Thorsten Holz, Felix C. Freiling
ACM Symposium on Applied Computing (SAC), Sierre, Switzerland, March 2010 [PDF]