How I found DOM XSS via postMessage on bing.com and received a reward by Microsoft Bug Bounty namcoder.com/blog/how-i-fou… #microsoft #bugbounty #bugbountytips

namcoder_com's tweet image. How I found DOM XSS via postMessage on bing.com and received a reward by Microsoft Bug Bounty 

namcoder.com/blog/how-i-fou…

#microsoft #bugbounty #bugbountytips

Nice, may i Dm? i had some question about postMessage xss's


You are welcome. Send me your question 😊


like in which position u are trying to trigger it with postMessage('message', '*'), how do u debug it then exploit it? like how u check do if the code is vulnerable, it's a bit hard for me to understand, like i found one there wasn't dangerous source and any origin and didn't pop


Yes. Put the breakpoint inside the listener on the “Sources” tab. Then send the test postMessage({},’*’) on the “Console” tab. You should have some knowledge about the JavaScript to debug. When you send the postmessage, it will trigger the breakpoint


United States トレンド
Loading...

Something went wrong.


Something went wrong.