video thumbnail 12:16
DO NOT USE alert(1) for XSS

2021-07-31

[public] 37.4K views, 9.20K likes, 46.0 dislikes audio only

channel thumbLiveOverflow

... and use alert(document.domain) or alert(window.origin) instead.

Blog post: https://liveoverflow.com/do-not-use-alert-1-in-xss/

Sponsored by Google for their Bug Hunter University: https://bughunters.google.com/learn/invalid-reports/web-platform/xss/5108550411747328

00:00 - Intro

00:47 - Why Do We Use Alert(1) for XSS?

02:25 - alert(1) Popup is NOT Proof of a Vulnerability!

03:07 - Invalid XSS Example 1 on Blogger

04:43 - Sandbox Subdomains

06:27 - Sandboxed iframes

08:29 - Invalid XSS Example 2 on Google Sites

09:50 - Why Should You Care About Invalid XSS Issues?

10:55 - Summary

11:55 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Intro
/youtube/video/KHwVjzWei1c?t=0
Why Do We Use Alert(1) for XSS?
/youtube/video/KHwVjzWei1c?t=47
alert(1) Popup is NOT Proof of a Vulnerability!
/youtube/video/KHwVjzWei1c?t=145
Invalid XSS Example 1 on Blogger
/youtube/video/KHwVjzWei1c?t=187
Sandbox Subdomains
/youtube/video/KHwVjzWei1c?t=283
Sandboxed iframes
/youtube/video/KHwVjzWei1c?t=387
Invalid XSS Example 2 on Google Sites
/youtube/video/KHwVjzWei1c?t=509
Why Should You Care About Invalid XSS Issues?
/youtube/video/KHwVjzWei1c?t=590
Summary
/youtube/video/KHwVjzWei1c?t=655
Outro
/youtube/video/KHwVjzWei1c?t=715
I’m moving, no videos sorry 17,544 views
/youtube/video/9CS3q0uG1LI
Support liveoverflow.com
https://liveoverflow.com/support
Hacking into Google's Network for $133,337 1,033,010 views
/youtube/video/g-JgA1hvJzA