Later archive addition
JSON hijacking for the modern web
Combines JavaScript Proxy traps with UTF-16BE script decoding to turn cross-origin JSON into undeclared variable names and recover their contents. Browser-specific prototype-chain tricks expose data in Edge, Chrome and Safari. The article also develops an injection-assisted variant without proxies and a CSP bypass, and explains why explicit response charsets prevent the charset attacks.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger
- Date
In the archive
Related sources
- OWASP London slides
- Demonstration: Edge variables
- Demonstration: second method
- Demonstration: Edge JSON
- Demonstration: Chrome 53
- Demonstration: Safari JSON
- Demonstration: without proxies
- Earlier variable-disclosure research
- Demonstration: multiple variables
- UTF-16BE CSP bypass demo
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host.