Collected research
A Magic Way of XSS in HTTP/2
Where two domains share one TLS certificate, an HTTP/2 server controlling one of them can use Server Push to push a response for the other, because the connection is authoritative for every name in the certificate. The pushed script waits in the browser cache and runs on the victim domain when the user navigates there, giving cross-origin XSS.
Record
- Published by
- tttang.com
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of tttang.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .