Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

00:00

Understanding DOMPurify Challenges in Web Security

This chapter explores the complexities and nuances of using DOMPurify for sanitization in JavaScript, discussing how varying configurations can impact security. The speakers highlight common mistakes and exploit techniques that can bypass DOMPurify, particularly focusing on context and improper HTML tag usage. Additionally, they delve into historical vulnerabilities related to jQuery and the implications of outdated libraries, emphasizing the importance of robust sanitization practices.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app