Critical Thinking - Bug Bounty Podcast cover image

Episode 73: Sandboxed IFrames and WAF Bypasses

Critical Thinking - Bug Bounty Podcast

00:00

Exploring Techniques with Sandbox IFrames and Frame Communication

The chapter delves into various innovative techniques involving sandboxed IFrames, including bypassing restrictions to access and exfiltrate data and leveraging sandbox attributes and window.open for communication and data access across web pages. Additionally, the discussion covers the concept of iFrame hijacking, highlighting how attackers can manipulate frame names and origins to deceive users into authorizing actions in deceptive iframes, leading to potential security vulnerabilities in web applications.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app