Critical Thinking - Bug Bounty Podcast cover image

Episode 26: Client-side Quirks & Browser Hacks

Critical Thinking - Bug Bounty Podcast

00:00

Google's CSP Evaluator

Google has the CSP evaluator.with Google, right? And if you put a whole content security, security policy string in there, it will check it and it'll tell you whether or not each part of it is safe. So certain domains like YouTube.com and stuff, they have alert, like popable, basically like gadgets that you can exploit to get an XSS. Maybe you could all, you could also say, oh, you would have to put something within a script tag in order to adhere to this nonce that's in the CSP or something like that. I don't think I've seen any tool like that.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app