Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

00:00

Sanitization Vulnerabilities and DOMPurify Exploits

This chapter examines the intricacies of using DOMPurify for sanitizing HTML input and the vulnerabilities that can emerge from its misuse. The discussion includes various techniques to bypass sanitization, such as node manipulation and character encoding strategies, highlighting how these can lead to severe security risks like cross-site scripting (XSS). Emphasizing the importance of awareness around sanitization processes and browser behaviors, the chapter guides listeners through complex scenarios that illustrate the challenges faced in web security.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app