Web Hack List

Top 10 winner

Google Search XSS

How did Masato find the Google Search XSS?

Explains how a Google Search XSS was found: fuzzing pairs of HTML tags through different parsing paths and diffing what a sandboxed iframe, DOMParser and createHTMLDocument produce, which exposes noscript and noembed parsing differently when scripting is disabled. The resulting parser differential mutates sanitized markup into script execution and bypassed two sanitizers.

Record

Document
How did Masato find the Google Search XSS?
Researcher
LiveOverflow
Published by
YouTube
Date
Format
Recording
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of LiveOverflow, first published at the original source. Preserved copies are kept so the citation survives its host.