Critical Thinking - Bug Bounty Podcast cover image

Episode 68: 0-days & HTMX-SS with Mathias

Critical Thinking - Bug Bounty Podcast

CHAPTER

HTML Syntax and Security Measures

The chapter explores the use of HTML syntax for security purposes, highlighting the shift from HX on to a new way using HX on colon error to prevent users from creating arbitrary HTML. It delves into vulnerabilities in web development frameworks like XSS in Angular and HTMX, referencing research findings by RioTac and Masato Kinugawa and discussing the risks of exploiting class attribute injections. The discussion covers bypassing security measures using data attributes, manipulating functions with 'Excessing Impossible Elements,' and escaping functions to prevent code injection in JavaScript environments.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner