Web Hack List

Collected research

XSS-Auditor --- the protector of unprotected and the deceiver of protected

XSS-Auditor — the protector of unprotected

Chrome's XSS Auditor was reverted from block mode to filter mode, so instead of stopping a page it silently strips the matched script. Reflecting a fake match aimed at a page's own defensive script deletes that script, and a CTF write-up shows this turning an otherwise blocked injection into working XSS.

Record

Document
XSS-Auditor — the protector of unprotected
Researcher
terjanq and @terjanq
Published by
Medium
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of terjanq and @terjanq, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .