How I found DOM XSS via postMessage on bing.com and received a reward by Microsoft Bug Bounty namcoder.com/blog/how-i-fou… #microsoft #bugbounty #bugbountytips

namcoder_com's tweet image. How I found DOM XSS via postMessage on bing.com and received a reward by Microsoft Bug Bounty 

namcoder.com/blog/how-i-fou…

#microsoft #bugbounty #bugbountytips

Nice, may i Dm? i had some question about postMessage xss's


You are welcome. Send me your question 😊


ah dm is closed, i am asking it here, ah when u looking for postMessage,u look at those on global listeners and going to the code, and finding addeventlistener("message then u look for sources? like window.open after the code that has message? like i didn't understand


For quick summary all listeners in a website, you could use the browser extension github.com/fransr/postMes… Quick look to find: .innerHTML or window.open or others sinks in my slides


United States Trends
Loading...

Something went wrong.


Something went wrong.