video thumbnail 13:45
Chaining Script Gadgets to Full XSS - All The Little Things 2/2 (web) Google CTF 2020

2020-10-08

[public] 22.2K views, 1.12K likes, 8.00 dislikes audio only

channel thumbLiveOverflow

In the second part we are building on top of what we have learned. We figure out how to craft something special out of a very limited script gadget. Eventually we can use it to leak the secret notes ID and notes content.

Part 1: /youtube/video/dZXaQKEE3A8

Challenge: https://capturetheflag.withgoogle.com/challenges/web-littlethings

Pasteurize: /youtube/video/Tw7ucd2lKBk

00:00 - Recap Part 1

00:20 - Start of the Attack Chain

00:54 - Control the Theme Callback

02:29 - Prior JSONP Capability Research

04:40 - innerHTML Breakthrough

06:13 - Content Security Policy Fail

07:19 - iframe CSP Bypass

08:31 - The Solution

10:09 - Chaining Three Gadgets

11:34 - Researching Cool XSS Techniques

12:00 - Solving the Challenge

13:25 - Outro

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/


Failed DOM Clobbering Research - All The Little Things 1/2 (web) Google CTF 2020 by LiveOverflow
/youtube/video/dZXaQKEE3A8
Recap Part 1
/youtube/video/UGtrpXk6QVU?t=0
Start of the Attack Chain
/youtube/video/UGtrpXk6QVU?t=20
Control the Theme Callback
/youtube/video/UGtrpXk6QVU?t=54
Prior JSONP Capability Research
/youtube/video/UGtrpXk6QVU?t=149
innerHTML Breakthrough
/youtube/video/UGtrpXk6QVU?t=280
Content Security Policy Fail
/youtube/video/UGtrpXk6QVU?t=373
iframe CSP Bypass
/youtube/video/UGtrpXk6QVU?t=439
The Solution
/youtube/video/UGtrpXk6QVU?t=511
Chaining Three Gadgets
/youtube/video/UGtrpXk6QVU?t=609
Researching Cool XSS Techniques
/youtube/video/UGtrpXk6QVU?t=694
Solving the Challenge
/youtube/video/UGtrpXk6QVU?t=720
Outro
/youtube/video/UGtrpXk6QVU?t=805
LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
I’m moving, no videos sorry 17,544 views
/youtube/video/9CS3q0uG1LI
Patreon patreon.com
https://www.patreon.com/join/liveoverflow
CTF video write-ups by LiveOverflow
/youtube/video/MpeaSNERwQA