I stumbled over a weird HTML behavior on Twitter and started to investigate it. Did I just stumble over a generic HTML Sanitizer bypass?
Get my handwritten font (advertisement)
Checkout our courses on (advertisement)
The Tweet:
Google XSS:
HTML Spec: #parse-error-invalid-first-character-of-tag-name
Chapters:
00:00 - Intro
01:09 - Sanitizing vs. Encoding
02:32 - Developing HTML Sanitizer Bypass
05:03 - Attacking DOMPurify
07:08 - Attacking Server-side Sanitizer
08:31 - HTML Parse Error Specification
10:08 - Potential Impact
11:55 -
=[ ❤️ Support ]=
→ per Video:
→ per Month:
2nd Channel:
=[ 🐕 Social ]=
→ Twitter:
→ Streaming:
→ TikTok: @liveoverflow_
→ Instagram:
→ Blog:
→ Subreddit:
→ Facebook:
1 view
0
0
1 month ago 00:13:49 1
Your Target Curve Might Be Wrong
2 months ago 00:30:04 1
Кеторолак (Ketorolac-Benefits) Справиться с Болью l Вред или Польза l Сильнодействующий!
2 months ago 00:12:15 9
ЛОВИМ когда НЕ КЛЮЕТ. Рыбалка с тестем.
3 months ago 00:09:12 1
My initial thoughts on the BRAND NEW iRacing McLaren 720s GT3!