Collected research
The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb...
The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…
Three bug-bounty chains built from bugs usually dismissed as low severity: CSS injection that hides a page and relabels a button so a clickjacked victim confirms an attacker's email; a dragged image whose data is rewritten and passed to jQuery html() for XSS, with a cookie bomb to stop an OAuth code being consumed; and login-logout CSRF that turns self-XSS into takeover.
Record
- Document
- The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…
- Researcher
- Renwa and @RenwaX23
- Published by
- Medium
- Date
- Topic
- XSS
In the archive
Related sources
- Cookie Bomb prerequisite Slides
Tags
This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .