Web Hack List

Top 10 winner

Google Search XSS

Explains how a Google Search XSS was found: fuzzing pairs of HTML tags through different parsing paths and diffing what a sandboxed iframe, DOMParser and createHTMLDocument produce, which exposes noscript and noembed parsing differently when scripting is disabled. The resulting parser differential mutates sanitized markup into script execution and bypassed two sanitizers.

Record

Researcher
LiveOverflow
Published by
YouTube
Date
Format
Recording

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of LiveOverflow, first published at the original source. Preserved copies are kept so the citation survives its host.