Revisiting XSS Sanitization
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the vulnerabilities and security challenges of online WYSIWYG editors in this Black Hat conference talk. Discover how to break the top 25 online rich-text editors powering thousands of web applications, including popular ones like TinyMCE, Jive, Froala, and CKEditor. Learn about real-world XSS bypasses on major platforms such as Twitter, Yahoo Email, Amazon, GitHub, Magento, and CNET. After demonstrating these vulnerabilities, gain insights into a practical and effective sanitizer solution based on just 11 characters and 3 regular expressions. Understand how this sanitizer can protect against XSS attacks in various contexts, including HTML, attribute, script (including JSON), style, and URL.
Syllabus
Revisiting XSS Sanitization
Taught by
Black Hat
Related Courses
Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security ChipBlack Hat via YouTube Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube