Critical Thinking - Bug Bounty Podcast cover image

Episode 26: Client-side Quirks & Browser Hacks

Critical Thinking - Bug Bounty Podcast

00:00

How to Inject JavaScript Into a Variable

This is regarding a specific context where you are injecting into oftentimes what ends up being as a JavaScript variable. The initial instinct would be to try to use double quotes or single quotes to escape that variable and get an XSS. But another one that I feel like people miss a decent bit is you have to still sanitize the HTML elements because, at the end of the day, you're inside of a script tag.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app