Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

00:00

Bypassing DOMPurify: Vulnerabilities and Exploits

This chapter explores the vulnerabilities associated with DOMPurify and the manipulation of web libraries such as jQuery and TinyMCE. It covers tactics used to exploit these libraries, focusing on character replacements and the impact of Unicode handling on security. The conversation emphasizes the need for developers to understand the intricacies of sanitization and the potential risks associated with DOMPurify's features and configurations.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app