Regular expressions considered harmful in client-side XSS filters

Daniel Bates


We propose a new filter design that achieves both high performance and high precision by blocking scripts after HTML parsing but before execution


