Web Hack List

Collected research

Why CSP Should be carefully crafted: Twitter XSS CSP Bypass

Paulos Yibelo - Hacking Research: Why CSP Should be carefully crafted: Twitter XSS & CSP Bypass

Twitter checked an app's Terms of Service URL with a regex that lacked a leading anchor, so data:text/html,<payload>#https:// passed and gave HTML injection. The CSP allowed unsafe-inline and trusted syndication.twitter.com, which serves JSONP: fetching a timeline widget with callback=alert runs attacker-chosen code, and Chrome executes it despite a Content-Disposition attachment header. The callback can also name a page method for same-origin method execution.

Record

Document
Paulos Yibelo - Hacking Research: Why CSP Should be carefully crafted: Twitter XSS & CSP Bypass
Published by
Paulos Yibelo - Hacking Research
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Paulos Yibelo - Hacking Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .