
Episode 9: Headless Browser SSRF & RebindMultiA Tool Release + Web3 Bug
Critical Thinking - Bug Bounty Podcast
00:00
How to Inject JavaScript Into a Headless Browser
Headless browser SSRS is a type of vulnerability that can be exploited. It works by running on the cli and doing all the browser stuff without actually showing a browser window. You can tell it to do whatever you want so if you could get JavaScript in there Your xss is gonna trigger, right? So yeah, it's definitely one to be one to be on the lookout for this sort of thing.
Transcript
Play full episode