<<

International Journal Multimedia and Image Processing (IJMIP), Volume 5, Issues 1/2, March/June 2015

Study on Attack Scenarios with HTML5

Soojin Yoon, Jonghun Jung, HwanKuk Kim Mobile Security R&D Team KISA (Korea Internet & Security Agency) Seoul, Korea

Abstract

The new Web standard HTML5 makes a Web 2. HTML5 page provide dynamic functions to users without additional plug-ins such as ActiveX, Flash and HTML is a programming language for writing Silverlight. Most attacks on Web browsers use such Web pages and the newest version of HTML. It was plug-ins. HTML5 provides the abilities that can be processed from 2009 and confirmed as a new Web substituted to plug-ins, so hackers focus their attacks standard on October 28, 2014. using HTML5. This paper surveys 16 attacks using The major features of HTML5 are semantic tags, HTML5 presented and shows their effects. CSS3 and new APIs. Additionally, three new attacks using HTML5 are Semantic tags offer information on Web content also discussed through tags. Before the tags existed, Web programmers used to write

tag to show content 1. Introduction type. For example, they wrote
to show a picture on a between div tags. In HTML is a computer language for Web pages. HTML5, a semantic tag
marks pictures or Most Web pages use HTML in writing or graphic content. Moreover, semantic tags like presentations. As Web use increases, the use of ,