YoVDO

Breaking XSS Mitigations Via Script Gadgets

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cross-Site Scripting (XSS) Courses Web Security Courses Content Security Policy Courses

Course Description

Overview

Explore a groundbreaking Web hacking technique that enables attackers to bypass most XSS mitigations by exploiting script gadgets. Delve into the concept of script gadgets, which are legitimate JavaScript pieces that process DOM elements, potentially leading to script execution. Learn about HTML sanitizers, Content Security Policies, and the expression process. Watch demonstrations and gain insights from security experts Sebastian Lekies, Krzysztof Kotowicz, and Eduardo Vela as they present their findings at Black Hat. Understand the implications of this novel approach for web security and discover potential countermeasures to protect against such attacks.

Syllabus

Introduction
What is XSS
What are Script Gadgets
The Problem
HTML Sanitizers
Script Gadgets
Summary
Unsafeeval
Content Security Policies
Expression Process
Demo
Sebastian
Summary Conclusion
Recap
Main Conclusion
Questions


Taught by

Black Hat

Related Courses

Web Hacking Expert - Full-Stack Exploitation Mastery
Packt via Coursera
OWASP Top 10: #7 XSS and #8 Insecure Deserialization
LinkedIn Learning
Web Security: Same-Origin Policies
LinkedIn Learning
Configuring Security Headers in ASP.NET and ASP.NET Core Applications
Pluralsight
Defeating Cross-site Scripting with Content Security Policy 2
Pluralsight