How I found DOM XSS via postMessage on bing.com and received a reward by Microsoft Bug Bounty namcoder.com/blog/how-i-fou… #microsoft #bugbounty #bugbountytips
Nice, may i Dm? i had some question about postMessage xss's
like in which position u are trying to trigger it with postMessage('message', '*'), how do u debug it then exploit it? like how u check do if the code is vulnerable, it's a bit hard for me to understand, like i found one there wasn't dangerous source and any origin and didn't pop
Yes. Put the breakpoint inside the listener on the “Sources” tab. Then send the test postMessage({},’*’) on the “Console” tab. You should have some knowledge about the JavaScript to debug. When you send the postmessage, it will trigger the breakpoint
United States 트렌드
- 1. Austin Reaves 47.8K posts
- 2. #LakeShow 3,054 posts
- 3. Trey Yesavage 37.2K posts
- 4. Jake LaRavia 5,679 posts
- 5. #LoveIsBlindS9 3,990 posts
- 6. doyoung 79.1K posts
- 7. jungwoo 104K posts
- 8. Blue Jays 61.9K posts
- 9. Rudy 9,218 posts
- 10. #Lakers 1,117 posts
- 11. Jeremy Lin N/A
- 12. #AEWDynamite 22.9K posts
- 13. Pelicans 4,409 posts
- 14. Happy Birthday Kat N/A
- 15. Snell 13.6K posts
- 16. Devin Booker 1,236 posts
- 17. #WorldSeries 66.8K posts
- 18. Wolves 64.1K posts
- 19. CALL 12 3,298 posts
- 20. Kacie 1,820 posts
Something went wrong.
Something went wrong.