从 infosec Mastodon 窃取密码——无需绕过 CSP
portswigger.net | 研究 | #credential-theft | #web-security | #xss | #html-injection | #sanitization | #mastodon
摘要
Gareth Heyes 讲述 Infosec Mastodon 凭据窃取案例:其 HTML 发帖过滤器存在注入问题,无需绕过 CSP 即可窃取凭据;文中剖析 title 属性与表情替换等 HTML 处理怪癖。
- 发布时间
- 收录时间
Skip to content