Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

00:00

Vulnerabilities in DOMPurify Sanitization

This chapter examines specific security vulnerabilities related to DOMPurify, particularly the improper sanitization of attributes that can lead to potential exploitations. It underscores the importance of understanding the operation of HTML sanitization tools rather than attempting to modify them, as such changes may introduce new vulnerabilities. Furthermore, the discussion covers complex techniques for bypassing DOM sanitization and emphasizes the need for a deep understanding of underlying code mechanisms to address these security issues.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app