Detecting web message misconfigurations for cross-domain credential theft
portswigger.net | research | #burp-suite | #credential-theft | #dom-invader | #oauth | #postmessage | #cross-domain
Summary
DOM Invader gains cross-domain leak detection: it inspects web messages and flags secrets from the URL being sent to other origins, automating the hunt for OAuth credential-theft misconfigurations.
- Published
- Collected
Skip to content