Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Hunting nonce-based CSP bypasses with dynamic analysis

Summary

How dynamic analysis flagged a nonce-based CSP bypass on portswigger.net: an injected element hijacked a querySelector to control a script URL, defeating what was thought to be a stricter policy.
Published
Collected

original ↗

Related coverage

back