DOM XSS in jQuery Selector Sink

DOM XSS in jQuery Selector Sink

z3nsh3ll

1 год назад

24,319 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

Temeturs
Temeturs - 13.11.2023 10:03

Fantastic! I was incredibly frustrated only to find out I used MY ID instead of the actual lab ID LOL Thought that would be funny to mention.

Ответить
Sexy and i know it
Sexy and i know it - 01.11.2023 22:12

Hey , your analysis is wrong. The problem isn't contains() , its where the user input ends up , inside jquery selector $() ; Proof of concept is simple , in the console , do this

$("<img src=1 onerror=alert(1)>");

Ответить
Станислав
Станислав - 23.10.2023 19:56

best👍👍👍👍👍

Ответить
Toby_TW
Toby_TW - 04.10.2023 11:48

With out your help, i struggled with this lab. Not convinced it should be 'apprentice level' on portswigger. Thankyou for your help.

Ответить
Frédérique Arseneau
Frédérique Arseneau - 01.10.2023 00:49

Thank you for the explanation that provides some context to all this!

Ответить
presequel
presequel - 01.09.2023 22:07

wow, this is amazing! i solved this box but without really knowing what i was doing but now your video makes it all clear! big thx :)

Ответить
anis wersighni
anis wersighni - 30.08.2023 12:17

why the lab was solved only by iframe ?

Ответить
Rosa
Rosa - 22.08.2023 22:02

Great explanation! How can we effectively analyze the js code? It contains so much data and functions

Ответить
Bloodmann
Bloodmann - 18.08.2023 12:31

It's a bit difficult to understand brother. Could you explain in simple terms? Even Though I work in cybersecurity, this is a bit tough.😁

Ответить
Nishan Maharjan
Nishan Maharjan - 22.07.2023 21:35

This a good video !!

Ответить
Somith
Somith - 21.07.2023 16:59

You are underrated

Ответить
aaron aguilar
aaron aguilar - 19.07.2023 10:41

Thank you for giving us some high level octane knowledge! You're the best!

Ответить
kiet
kiet - 21.06.2023 20:01

Thank you for the clear and very informative video.🎉🎉

Ответить
galaxy nn
galaxy nn - 21.06.2023 09:01

man this one was super aennoying

Ответить
Amit
Amit - 18.06.2023 10:54

great explanation, thanks mate

Ответить
Pranjal Ruhela
Pranjal Ruhela - 17.06.2023 14:30

why was this in the apprentice level though...its actually harder than most apprentice labs in XSS sections

Ответить
Sauer Voussoir
Sauer Voussoir - 22.05.2023 08:55

Very precise explanation, why do we need that iframe code?

Ответить
Sam
Sam - 06.02.2023 18:08

Awesome explanation, thanks mate!

Ответить