Web Hack List

Collected research

Dont Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets

AppSec EU 2017 Don't Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets by Sebastian Lekies

Script gadgets are legitimate JavaScript fragments inside popular frameworks that pick up injected, script-free HTML and turn it into executing code. Because the injected markup carries no script tag or event handler, HTML sanitisers, web application firewalls, browser XSS filters and CSP all let it through. The authors find such gadgets in most modern frameworks and across many live sites.

Record

Document
AppSec EU 2017 Don't Trust The DOM: Bypassing XSS Mitigations Via Script Gadgets by Sebastian Lekies
Researcher
Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns
Published by
raw.githubusercontent.com
Date
Format
Recording
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sebastian Lekies, Krzysztof Kotowicz, Samuel Groß, Eduardo A. Vela Nava and Martin Johns, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .