Critical Thinking - Bug Bounty Podcast cover image

Episode 58: Youssef Sammouda - Client-Side & ATO War Stories

Critical Thinking - Bug Bounty Podcast

00:00

Browser Security Vulnerabilities and Cross-Origin Communication

The chapter explores advanced techniques related to account takeover vulnerabilities, focusing on self-excess and XSS attacks, leaking OAuth tokens, and manipulating same site cookie policies. It delves into the technical aspects of client-side security, discussing session cookies, relogin sessions, and centralized login systems. The conversation also delves into the intricacies of message ports, message channels, passing message ports in post messages, and manipulating window frames and references across different origins.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app