Collected research
Why CSP Should be carefully crafted: Twitter XSS CSP Bypass
Paulos Yibelo - Hacking Research: Why CSP Should be carefully crafted: Twitter XSS & CSP Bypass
Twitter checked an app's Terms of Service URL with a regex that lacked a leading anchor, so data:text/html,<payload>#https:// passed and gave HTML injection. The CSP allowed unsafe-inline and trusted syndication.twitter.com, which serves JSONP: fetching a timeline widget with callback=alert runs attacker-chosen code, and Chrome executes it despite a Content-Disposition attachment header. The callback can also name a page method for same-origin method execution.
Record
- Document
- Paulos Yibelo - Hacking Research: Why CSP Should be carefully crafted: Twitter XSS & CSP Bypass
- Published by
- Paulos Yibelo - Hacking Research
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Paulos Yibelo - Hacking Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .