Web Hack List

Collected research

Rook to XSS: How I hacked chess.com with a rookie exploit

A bug bounty case study showing that HTML sanitisation applied before later server-side rewriting can be undone. A large chess site re-uploaded remote images referenced in its rich-text editor, and the rewritten background-image URL broke out of the style attribute to inject unfiltered event-handler attributes; heavy character filtering was then bypassed using regular-expression source strings to build cookie-stealing payloads.

Record

Researcher
Jacob
Published by
Skii.dev
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jacob, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .