Collected research
Dont Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets
AppSec EU 2017 Don't Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets by Sebastian Lekies
Script gadgets are legitimate JavaScript fragments inside popular frameworks that pick up injected, script-free HTML and turn it into executing code. Because the injected markup carries no script tag or event handler, HTML sanitisers, web application firewalls, browser XSS filters and CSP all let it through. The authors find such gadgets in most modern frameworks and across many live sites.
Record
- Document
- AppSec EU 2017 Don't Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets by Sebastian Lekies
- Researcher
- Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns
- Published by
- raw.githubusercontent.com
- Date
- Format
- Recording
- Topic
- XSS
In the archive
Related sources
- ccs gadgets Whitepaper
- AppSec EU 2017 Don't Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets by Sebastian Lekies
- OWASP BeNeLux Day Don't trust the DOM: Bypassing XSS mitigations via script gadgets by S. Lekies
Tags
This page is the archive's own catalogue record. The research is the work of Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .