Web Hack List

Collected research

The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb...

The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…

Three bug-bounty chains built from bugs usually dismissed as low severity: CSS injection that hides a page and relabels a button so a clickjacked victim confirms an attacker's email; a dragged image whose data is rewritten and passed to jQuery html() for XSS, with a cookie bomb to stop an OAuth code being consumed; and login-logout CSRF that turns self-XSS into takeover.

Record

Document
The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF…
Researcher
Renwa and @RenwaX23
Published by
Medium
Date
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .