Critical Thinking - Bug Bounty Podcast cover image

Episode 76: Match & Replace - HTTP Proxies' Most Underrated Feature

Critical Thinking - Bug Bounty Podcast

00:00

Exploring Client-Side Exploits and Cookie-Based Vulnerabilities

The chapter delves into a bug concerning Google OAuth implementation and its implications, focusing on a client-side exploit chain involving CSP, cookies, cookie tossing, post-based attacks, and XSS. They discuss the importance of understanding browser security vulnerabilities and highlight the discovery of a cookie-based XSS vulnerability in Zoom. The speakers emphasize the significance of testing cookie values, combining vulnerabilities, and leveraging different techniques like cookie tossing for successful exploit outcomes.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app