Solution for “A Weird XSS Case”
ID: 210fab29-6c19-50dd-a605-cc3dffd579f8
STIX ID: report--210fab29-6c19-50dd-a605-cc3dffd579f8
Feed Name: YesWeHack Blog
A detailed analysis of a cross-site scripting (XSS) challenge on the BSidesDublin 2019 site: the author reviews the JavaScript input validation, finds bypasses using non-ASCII characters that map to ASCII through case conversions, crafts payloads to manipulate the DOM and invoke JavaScript without lowercase letters, and demonstrates working exploit payloads (including a Function-constructor and pseudo-URL techniques). The write-up includes code excerpts, the logic of the filters, and multiple successful bypasses and proofs of concept.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
