video thumbnail 9:15
Fuzzing Browsers for weird XSS Vectors

2019-04-14

[public] 62.3K views, 2.71K likes, 14.0 dislikes audio only

channel thumbLiveOverflow

We have a look at another interesting XSS vector due to weird Firefox parsing, and then explore how researchers find this stuff.

Gareth's tweet: https://twitter.com/garethheyes/status/1112661895067156481

insertScript's vector: http://shazzer.co.uk/vector/lt-eating-char

-=[ ā¤ļø Support ]=-

→ per Video: https://www.patreon.com/join/liveoverflow

→ per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join

-=[ šŸ”“ Stuff I use ]=-

→ Microphone:* https://geni.us/ntg3b

→ Graphics tablet:* https://geni.us/wacom-intuos

→ Camera#1 for streaming:* https://geni.us/sony-camera

→ Lens for streaming:* https://geni.us/sony-lense

→ Connect Camera#1 to PC:* https://geni.us/cam-link

→ Keyboard:* https://geni.us/mech-keyboard

→ Old Microphone:* https://geni.us/mic-at2020usb

US Store Front:* https://www.amazon.com/shop/liveoverflow

-=[ šŸ• Social ]=-

→ Twitter: https://twitter.com/LiveOverflow/

→ Website: https://liveoverflow.com/

→ Subreddit: https://www.reddit.com/r/LiveOverflow/

→ Facebook: https://www.facebook.com/LiveOverflow/

-=[ šŸ“„ P.S. ]=-

All links with "*" are affiliate links.

LiveOverflow / Security Flag GmbH is part of the Amazon Affiliate Partner Programm.


How did Masato find the Google Search XSS? by LiveOverflow
/youtube/video/gVrdE6g_fa8
HTML parser/sanititer
/youtube/video/yq_P3dzGiK4?t=112
researcher: mental model of a theoretical
/youtube/video/yq_P3dzGiK4?t=159
research example #2 sing onerror="alert(1)" src=
/youtube/video/yq_P3dzGiK4?t=319
research exarople #3
/youtube/video/yq_P3dzGiK4?t=355
what did we do? • posed a research question
/youtube/video/yq_P3dzGiK4?t=380
LiveOverflow just a wannabe hacker... making videos about various IT security topics and participating in hacking competitions. -=[ ā¤ļø Support me ]=- Patreon per Video: https://www.patreon.com/join/liveoverflow YouTube Membership per Month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join -=[ šŸ“„ Imprint ]=- Security Flag GmbH Celsiusstr. 72 12207 Berlin Germany
/youtube/channel/UClcE-kVhqyiHCcjYwcpfj9w
I’m moving, no videos sorry 17,489 views
/youtube/video/9CS3q0uG1LI
Patreon patreon.com
https://www.patreon.com/join/liveoverflow
Identifying Good Research to actually Learn Something - Cross-site Scripting 170,089 views
/youtube/video/eQFbG6CwwdI