Critical Thinking - Bug Bounty Podcast cover image

Episode 26: Client-side Quirks & Browser Hacks

Critical Thinking - Bug Bounty Podcast

00:00

JavaScript CSP Evaluator

There's nothing in the browser spec or anywhere that states that you have to have valid JavaScript to eat your script tags. You could just close a script tag and keep like put elements in the page. And then, you know, get XSS via like clicker and on hover and on the event handler as well. CSP is kind of a double edged sword sometimes with that sort of thing.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app