Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

CHAPTER

Sanitization Vulnerabilities and DOMPurify Exploits

This chapter examines the intricacies of using DOMPurify for sanitizing HTML input and the vulnerabilities that can emerge from its misuse. The discussion includes various techniques to bypass sanitization, such as node manipulation and character encoding strategies, highlighting how these can lead to severe security risks like cross-site scripting (XSS). Emphasizing the importance of awareness around sanitization processes and browser behaviors, the chapter guides listeners through complex scenarios that illustrate the challenges faced in web security.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner