This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)!
Link 👇
mizu.re/post/explori...
1/2
This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)!
Link 👇
mizu.re/post/explori...
1/2
They are doing an amazing job at tracking all new potential attacks. We respect and rely on their findings.
He’s the maintainer of ~20 OSS projects, including SVGR.
SVGR transforms SVG files into React components. It also works with Webpack, Vite, and Next.js.
As part of our open source donation program, we donated to Devon to thank him for his work and impact on the community.
He's also the creator of Parcel and Lightning CSS.
They are doing an amazing job at tracking all new potential attacks. We respect and rely on their findings.
- Allow multiple pipeline embed
- Short links for sharing/sync
- Support for DomPurify triggers
- User settings
Give it a try and share your findings!
yeswehack.github.io/Dom-Explorer
- Allow multiple pipeline embed
- Short links for sharing/sync
- Support for DomPurify triggers
- User settings
Give it a try and share your findings!
yeswehack.github.io/Dom-Explorer
#javascript #frontend #buildinpublic #ui #cybersecurity
stackblitz.com/edit/rimmel-...
#javascript #frontend #buildinpublic #ui #cybersecurity
stackblitz.com/edit/rimmel-...
portswigger-labs.net/mxss/
Set HTMLSanitizer ✅
Auto update ✅
I'm trying to break it, I encourage you to break it too
portswigger-labs.net/mxss/
Set HTMLSanitizer ✅
Auto update ✅
I'm trying to break it, I encourage you to break it too
📚 mizu.re/post/explori...
☁️ devanshbatham.hashnode.dev/fragility-of...
🫙 www.wiz.io/blog/nvidia-...
🐍 www.reversinglabs.com/blog/rl-iden...
🎥 brutecat.com/articles/lea...
📚 mizu.re/post/explori...
☁️ devanshbatham.hashnode.dev/fragility-of...
🫙 www.wiz.io/blog/nvidia-...
🐍 www.reversinglabs.com/blog/rl-iden...
🎥 brutecat.com/articles/lea...
Before releasing it, I would like to share a small challenge 🚩
Challenge link 👇
challenges.mizu.re/xss_04.html
1/2
Before releasing it, I would like to share a small challenge 🚩
Challenge link 👇
challenges.mizu.re/xss_04.html
1/2
https://github.com/cure53/DOMPurify/blob/main/demos/hooks-mentaljs-demo.html
https://github.com/cure53/DOMPurify/blob/main/demos/hooks-mentaljs-demo.html
www.youtube.com/watch?v=aLNx...
www.youtube.com/watch?v=aLNx...
mizu.re/post/explori...
mizu.re/post/explori...
www.youtube.com/watch?v=KffI...
www.youtube.com/watch?v=KffI...
Includes:
- Update dompurify (HTML sanitize module) to the latest version
- Add groups mapping for the Azure AD auth module
- Fix code wrapping in print view
See github.com/requarks/wik... for details.
Includes:
- Update dompurify (HTML sanitize module) to the latest version
- Add groups mapping for the Azure AD auth module
- Fix code wrapping in print view
See github.com/requarks/wik... for details.
Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅
https://github.com/cure53/DOMPurify/releases/tag/3.4.1
Among them, a better test suite, a small fuzzer, several fixes and hardenings, and as usually we hope all went well 😅
https://github.com/cure53/DOMPurify/releases/tag/3.4.1
www.youtube.com/watch?v=fnYS...
www.youtube.com/watch?v=fnYS...
Btw! If you wonder how could this be abused, I recommend you looking at: mizu.re/post/explori... 😉
3/3
Btw! If you wonder how could this be abused, I recommend you looking at: mizu.re/post/explori... 😉
3/3