ArticleWhat is CORS and how does it work?
What is CORS and how does it work?: 🔎 What is CORS? CORS (Cross Origin Resource Sharing) is a mechanism that allows a web server to explicitly permi…
Practical security research, write-ups, guides, and lessons learned.
ArticleWhat is CORS and how does it work?: 🔎 What is CORS? CORS (Cross Origin Resource Sharing) is a mechanism that allows a web server to explicitly permi…
ArticleDOM XSS using web messages and a JavaScript URL: This lab demonstrates a DOM based redirection vulnerability that is triggered via web messaging. • P…
ArticleKnowledge about DOM based and sinks: In our demonstration page, we have the following source code: • Knowledge • knowledge, sinks
ArticleMore knowledge about DOM : I still need more understanding of DOM, • Knowledge • DOM, DOM based • dom, dom based
ArticleWebListeners: 📝 What I Learned In this article I explored how an EventListener works together with postMessage in JavaScript. This also involved ver…
ArticleDOM XSS using web messages and a JavaScript URL: This lab demonstrates a DOM based redirection vulnerability triggered by web messaging. • PortSwigge…
ArticleCSRF with broken Referer validation: This lab's email change functionality is vulnerable to CSRF. It attempts to detect and block cross domain reques…
ArticleCSRF where Referer validation depends on header being present: This lab's email change functionality is vulnerable to CSRF. Although the application…
ArticleCSRF where token is duplicated in cookie: This lab’s email change functionality is vulnerable to CSRF. It uses the insecure "double submit" CSRF prev…
ArticleLearn about Sinks: This article demonstrates how different DOM sinks (Document, Location, and Execution) can introduce DOM based XSS vulnerabilities.…
ArticleKnowledge about DOM based stuff: ❓ Questions Covered What is DOM based XSS and how does it work? How to prevent it? How to detect DOM based XSS? What…
ArticleCSRF where token is tied to non session cookie: This lab's email change functionality is vulnerable to CSRF. It uses tokens to try to prevent CSRF at…