
Episode 36: Bug Bounty Ethics & CT Exclusive Bug Reports
Critical Thinking - Bug Bounty Podcast
00:00
Controlling Browser Behavior and Leveraging XSS Vulnerabilities
This chapter explores the use of response headers to control browser behavior, as well as the potential for leveraging XSS vulnerabilities to manipulate functions and properties within the window and escape JavaScript sandboxes. The speakers also discuss a trick they used to extract an ATO (Authorization Token) by creating an iframe and overwriting the fetch function to intercept API calls.
Transcript
Play full episode