Главная
Study mode:
on
1
Introduction
2
What is XSS
3
What are Script Gadgets
4
The Problem
5
HTML Sanitizers
6
Script Gadgets
7
Summary
8
Unsafeeval
9
Content Security Policies
10
Expression Process
11
Demo
12
Sebastian
13
Summary Conclusion
14
Recap
15
Main Conclusion
16
Questions
Description:
Explore a groundbreaking Web hacking technique that enables attackers to bypass most XSS mitigations by exploiting script gadgets. Delve into the concept of script gadgets, which are legitimate JavaScript pieces that process DOM elements, potentially leading to script execution. Learn about HTML sanitizers, Content Security Policies, and the expression process. Watch demonstrations and gain insights from security experts Sebastian Lekies, Krzysztof Kotowicz, and Eduardo Vela as they present their findings at Black Hat. Understand the implications of this novel approach for web security and discover potential countermeasures to protect against such attacks.

Breaking XSS Mitigations Via Script Gadgets

Black Hat
Add to list
0:00 / 0:00