Collected research
XSS-Auditor --- the protector of unprotected and the deceiver of protected
XSS-Auditor — the protector of unprotected
Chrome's XSS Auditor was reverted from block mode to filter mode, so instead of stopping a page it silently strips the matched script. Reflecting a fake match aimed at a page's own defensive script deletes that script, and a CTF write-up shows this turning an otherwise blocked injection into working XSS.
Record
- Document
- XSS-Auditor — the protector of unprotected
- Researcher
- terjanq and @terjanq
- Published by
- Medium
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of terjanq and @terjanq, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .