[WEB SECURITY] DOMinator - The DOMXss Analyzer Tool - is finally public

Stefano Di Paola stefano.dipaola at wisec.it
Wed May 18 13:12:58 EDT 2011

What is DOMinator?
DOMinator is a Firefox based software for analysis and identification of
DOM Based Cross Site Scripting issues (DOMXss).
It is the first runtime tool which can help security testers to identify

How it works?

It uses dynamic runtime tainting model on strings and can trace back
taint propagation operations in order to understand if a DOMXss
vulnerability is actually exploitable.

If you're interested in it continue the reading here:

More whitepapers in the next days.


Stefano Di Paola
Software & Security Engineer

Owasp Italy R&D Director

Web: www.wisec.it
Twitter: http://twitter.com/WisecWisec

More information about the websecurity mailing list