Web Hack List

Collected research

Evading CSP with DOM-based dangling markup

Dangling markup normally dies under a strict CSP because no external resource may load. Injecting an unterminated base target attribute, or a form target, instead captures the following page markup into window.name, so a single victim click hands CSRF tokens and other secrets to an attacker page even under default-src 'none'.

Record

Researcher
Gareth Heyes
Published by
PortSwigger Research
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .