Collected research
Rook to XSS: How I hacked chess.com with a rookie exploit
A bug bounty case study showing that HTML sanitisation applied before later server-side rewriting can be undone. A large chess site re-uploaded remote images referenced in its rich-text editor, and the rewritten background-image URL broke out of the style attribute to inject unfiltered event-handler attributes; heavy character filtering was then bypassed using regular-expression source strings to build cookie-stealing payloads.
Record
- Researcher
- Jacob
- Published by
- Skii.dev
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Jacob, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .