Later archive addition
How to bypass CSP nonces with DOM XSS
The article shows how repeatable DOM injection can use CSS attribute selectors to recover a CSP nonce and then execute script with that nonce. It demonstrates the chain with persistent, postMessage-driven, HTTP-inclusion, and location-hash DOM XSS cases.
Record
- Researcher
- Eduardo Vela and Sebastian Lekies
- Published by
- sirdarckcat
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Eduardo Vela and Sebastian Lekies, first published at the original source. Preserved copies are kept so the citation survives its host.