Critical Thinking - Bug Bounty Podcast cover image

Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans

Critical Thinking - Bug Bounty Podcast

00:00

Exploiting XSS Vulnerabilities in iframed Domains

This chapter explores the concept of an iframe sandwich, where an attacker can exploit an XSS vulnerability on an iframed subdomain to control the content of the victim domain. The hosts discuss different scenarios and techniques to leverage XSS attacks within iframe contexts, emphasizing the importance of understanding the same origin policy and communication between iframes. They also touch on related topics such as SSRF and open redirects.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app