Web Hack List

Collected research

Hijacking service workers via DOM Clobbering

Service workers configured from the page, by a query-string parameter or by the innerText of an element fetched with document.getElementById, can be made to pass an attacker host to importScripts(). Injecting an html or body tag carrying the same id clobbers that lookup, so injected markup alone yields persistent site takeover that also evades HTML filters and CSP.

Record

Researcher
Gareth Heyes
Published by
PortSwigger Research
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .