Web Hack List

Collected research

Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild

A reflected XSS on a sibling domain is used to postMessage into an auth portal whose listener writes attacker HTML through innerHTML; DOM clobbering of an undeclared global, via a named iframe holding an anchor, makes a static fragment served without CSP headers load an attacker-controlled script. The chain turns a permissive origin regex into script execution on the authenticated origin.

Record

Researcher
Brett Buerhaus, Sam Curry and Maik Robert
Published by
buer.haus
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Brett Buerhaus, Sam Curry and Maik Robert, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .