Explore tweets tagged as #DOMPurify
✅ Built a blogging platform from scratch!. 🛠️ Tech Stack: EJS (HTML, CSS), Node.js, MongoDB. 🎯 Features: Create, Edit, Delete Articles. 🔐 Safe & Secure using DOMPurify + JSDOM. 🔗 #TechProjects #WebDev #CodingCommunity
1
0
2
I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜. The research article is available here: The slides are available here: 1/3
18
180
699
Google fixed the Referrer Policy override technique in under 10 days. During that window, I found the latest version of DOMPurify on a public HackerOne program, used the trick to demonstrate impact and exploit the OAuth flow, and earned a ~$4K bounty :D
A fix from Google was released today. Part of the issue was due to my misunderstanding based on previous reports. Big thanks to chromium team for the quick resolve .I hope everyone had some fun, and apologies to the triagers on HackerOne XD
5
10
207
CSS Data Exfiltration leads to Account Takeover (2x$4850 in two different routes). the input was placed in DOMPurify (last ver) protected area, we (@AmirMSafari) used <style> tag to leak OAuth token with a sandbox in page. we will publish a detailed writeup tomorrow night :]
26
41
723
Awesome technique by @slonser_! With this method, you can leak sensitive data using just an 'img' tag, even if the target uses DOMPurify and CSS data exfiltration is not possible
Today I used a technique that’s probably not widely known in the community. In what cases could code like this lead to a vulnerability? ->
6
41
254
I've seen people crushing it lately with server-side XSS inside a headless browser. It almost always results in RCE or crazy SSRF. But first you need to find XSS, and a lot of time you're running up against a sanitizer - DOMPurify. The latest @ctbbpodcast episode covers how to.
4
12
203
A recent vulnerability, CVE 2024 47875, was discovered in DOMPurify. The good news? The issue has already been patched in versions 2.50, 3.13, and any newer releases. 🛡️ .#dompurify #securityvulnerability #XSS #crosssitescripting #appsec #opensourcesecurity #securecoding
0
0
1