Web Hack List

Collected research

A Magic Way of XSS in HTTP/2

Where two domains share one TLS certificate, an HTTP/2 server controlling one of them can use Server Push to push a response for the other, because the connection is authoritative for every name in the certificate. The pushed script waits in the browser cache and runs on the victim domain when the user navigates there, giving cross-origin XSS.

Record

Published by
tttang.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of tttang.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .