Web Hack List

Later archive addition

XSS Persistence using JSONP and ServiceWorkers

The article chains XSS with an unfiltered same-origin JSONP endpoint to register attacker-controlled code as a service worker. The worker can persist beyond the original injection and intercept or rewrite later responses, creating a durable in-browser backdoor.

Record

Researcher
Stuart Larsen
Published by
c0nrad's corner
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Stuart Larsen, first published at the original source. Preserved copies are kept so the citation survives its host.