Collected research
Exploiting POST-based XSSI
A service worker on the attacker's own page intercepts its own script include and reissues it as a credentialed cross-origin POST with a safelisted content type. Any endpoint that answers a POST with valid JavaScript then leaks its contents to the including page, extending cross-site script inclusion beyond GET requests.
Record
- Researcher
- @1lastBr3ath and Prakash
- Published by
- DON'T BE A 5KIDDO, BE A HACKER
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @1lastBr3ath and Prakash, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .