Critical Thinking - Bug Bounty Podcast cover image

Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans

Critical Thinking - Bug Bounty Podcast

CHAPTER

Exploiting XSS Vulnerabilities in iframed Domains

This chapter explores the concept of an iframe sandwich, where an attacker can exploit an XSS vulnerability on an iframed subdomain to control the content of the victim domain. The hosts discuss different scenarios and techniques to leverage XSS attacks within iframe contexts, emphasizing the importance of understanding the same origin policy and communication between iframes. They also touch on related topics such as SSRF and open redirects.

00:00
Transcript
Play full episode

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner