Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone
ID: 632456a4-d302-58d7-b939-45745968600d
STIX ID: report--632456a4-d302-58d7-b939-45745968600d
Feed Name: Black Hills Infosec Blog
This blog explains how JSONP endpoints can be abused to bypass Content Security Policy (CSP) and achieve XSS, demonstrates the technique with examples (including Google’s JSONP endpoint), and introduces two tools — JSONPeek for detecting JSONP callback parameters and CSP B Gone for automating CSP bypass discovery using a curated dataset of endpoints; the author also describes using BigQuery and headless testing to harvest and validate thousands of candidate endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
