Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

CHAPTER

Understanding DOMPurify Challenges in Web Security

This chapter explores the complexities and nuances of using DOMPurify for sanitization in JavaScript, discussing how varying configurations can impact security. The speakers highlight common mistakes and exploit techniques that can bypass DOMPurify, particularly focusing on context and improper HTML tag usage. Additionally, they delve into historical vulnerabilities related to jQuery and the implications of outdated libraries, emphasizing the importance of robust sanitization practices.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner