Critical Thinking - Bug Bounty Podcast cover image

Episode 68: 0-days & HTMX-SS with Mathias

Critical Thinking - Bug Bounty Podcast

00:00

HTML Syntax and Security Measures

The chapter explores the use of HTML syntax for security purposes, highlighting the shift from HX on to a new way using HX on colon error to prevent users from creating arbitrary HTML. It delves into vulnerabilities in web development frameworks like XSS in Angular and HTMX, referencing research findings by RioTac and Masato Kinugawa and discussing the risks of exploiting class attribute injections. The discussion covers bypassing security measures using data attributes, manipulating functions with 'Excessing Impossible Elements,' and escaping functions to prevent code injection in JavaScript environments.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app