

Episode 47: CSP Research, Iframe Hopping, and Client-side Shenanigans
4 snips Nov 30, 2023
The podcast discusses the struggles of bug bounty hunting, including feeling disconnected after live hacking events and the frustration of not finding bugs. They highlight the significance of perseverance and getting into a flow state. They explore topics such as client-side paths, manipulating webpack map files, and exploiting XSS vulnerabilities in iframed domains. They also discuss the benefits of Google's extension for hacking and techniques for bypassing Content Security Policy.
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10
Introduction
00:00 • 2min
The Struggles of Bug Bounty Hunting
01:50 • 12min
Complexities of Authentication Systems and the Launch of Discord Community
13:38 • 15min
Tool for extracting Next.js routes and the Importance of Client-side Paths
28:46 • 3min
Manipulating Webpack Map Files and Lazy Loaded JavaScript
31:21 • 3min
Frustrations with Scope Control in Kaido
33:51 • 18min
Exploiting XSS Vulnerabilities in iframed Domains
51:29 • 11min
Exploring Protobuf and the Benefits of Google's Extension for Hacking
01:02:47 • 2min
Lowering the Bar for Hacking
01:04:42 • 15min
Exploiting the Same-Origin Policy and Bypassing CSP
01:19:29 • 12min