MXSS Explained: Server Side HTML Sanitizers are Doomed to Fail with this XSS!

  Рет қаралды 2,704

Mrgavyadha

Mrgavyadha

Күн бұрын

Пікірлер: 15
@LiveOverflow
@LiveOverflow 3 ай бұрын
amazing work! Keep going!
@mrgavyadha
@mrgavyadha 3 ай бұрын
💪
@eingengraou1288
@eingengraou1288 3 ай бұрын
he's doing tutorials like you, i love how you explain why the bug happens , now your video just shows that even if a site uses front end frameworks with saniters they're still hackable
@abdulx01
@abdulx01 3 ай бұрын
Nice.. This is very complex and underrated vulnerability that every researchers avoid. Thanks for sharing, I'm very excited and interested to learn about this mXSS. Finally someone made it. Thank guru. ❤
@chiragartani
@chiragartani 3 ай бұрын
Very hard to create videos like this, I can understand. Amazing video, Keep it up brother👌🙏
@vibhakarvaddi1858
@vibhakarvaddi1858 3 ай бұрын
Really amazed by the concept and your explanation anna. Keep going
@0xphsi
@0xphsi 3 ай бұрын
Excellent explanation of a rather complex issue, good stuff!
@amoh96
@amoh96 3 ай бұрын
really good video explain well keep more videos like this
@0xrudrapratap
@0xrudrapratap 3 ай бұрын
Good video, great animations
@nodistractionsjustgoandstu1842
@nodistractionsjustgoandstu1842 3 ай бұрын
I made a challenge on this for IRON CTF 2024 its on oct 5
@pareshankoko
@pareshankoko 3 ай бұрын
nice explanation
@RR-bz8bi
@RR-bz8bi 3 ай бұрын
function foo(string $value): bool { $paterns = ["]+(?:\s+on[a-z]+)"]; $invalid = 0; foreach ($paterns as $patern) { if (preg_match("/{$patern}/i", $value)) { $invalid++; } } return $invalid == 0; } $string = ''; foo($string); // return false;
@mrgavyadha
@mrgavyadha 3 ай бұрын
alert(1) :)
@RR-bz8bi
@RR-bz8bi 3 ай бұрын
@@mrgavyadha $paterns = [ "]*>", "]+(?:\s+on[a-z]+)", // etc. ]; :)
@kushalkumar6414
@kushalkumar6414 5 күн бұрын
@@RR-bz8bi alert(1)
A date with Boss || Part - 13 || Ravi Siva Teja || Viraajitha || Infinitum Media
21:52
Война Семей - ВСЕ СЕРИИ, 1 сезон (серии 1-20)
7:40:31
Семейные Сериалы
Рет қаралды 1,6 МЛН
БАБУШКА ШАРИТ #shorts
0:16
Паша Осадчий
Рет қаралды 4,1 МЛН
Best of CES 2025
14:50
The Verge
Рет қаралды 633 М.
MXSS Part 2: Why Client-Side HTML Sanitization is hard
19:25
Mrgavyadha
Рет қаралды 1,7 М.
Hacking Discord for $5000 Bounty
24:50
Mrgavyadha
Рет қаралды 83 М.
5k Clickjacking, Encryption Oracles, and Cursor for PoCs (Ep. 90)
51:42
Critical Thinking - Bug Bounty Podcast
Рет қаралды 1,9 М.
I reimplemented REACT SERVER COMPONENTS in ASSEMBLY
20:35
Neo Goose
Рет қаралды 9 М.
Hacking Story  - Returning From The Dead
4:57
BeerBiceps
Рет қаралды 947 М.
APIs for Beginners - How to use an API (Full Course / Tutorial)
3:07:07
freeCodeCamp.org
Рет қаралды 3,1 МЛН
Why OOP is evolving(and why it's a good thing)
7:35
TMF
Рет қаралды 16 М.
Война Семей - ВСЕ СЕРИИ, 1 сезон (серии 1-20)
7:40:31
Семейные Сериалы
Рет қаралды 1,6 МЛН