Web Hack List

Collected research

Neatly bypassing CSP

Neatly bypassing CSP ✔️

A page with a strict CSP can still be attacked by framing a same-origin path that returns no CSP header, such as a CSS file, robots.txt or a server error page, because browsers wrap those responses in HTML. Script written into that frame runs unrestricted and can read the parent page; oversized URLs or cookies are used to force the error responses.

Record

Document
Neatly bypassing CSP ✔️
Researcher
@bo0om
Published by
Wallarm
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @bo0om, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .