Web Hack List

Collected research

JSON hijacking for the modern web

Combines JavaScript Proxy traps with UTF-16BE script decoding to turn cross-origin JSON into undeclared variable names and recover their contents. Browser-specific prototype-chain tricks expose data in Edge, Chrome and Safari. The article also develops an injection-assisted variant without proxies and a CSP bypass, and explains why explicit response charsets prevent the charset attacks.

Record

Researcher
Gareth Heyes
Published by
PortSwigger
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .