Critical Thinking - Bug Bounty Podcast cover image

Episode 111: How to Bypass DOMPurify in Bug Bounty with Kevin Mizu

Critical Thinking - Bug Bounty Podcast

CHAPTER

Bypassing DOMPurify: Vulnerabilities and Exploits

This chapter explores the vulnerabilities associated with DOMPurify and the manipulation of web libraries such as jQuery and TinyMCE. It covers tactics used to exploit these libraries, focusing on character replacements and the impact of Unicode handling on security. The conversation emphasizes the need for developers to understand the intricacies of sanitization and the potential risks associated with DOMPurify's features and configurations.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner