4.2. XSSΒΆ
- 4.2.1. Classification
- 4.2.2. Hazards
- 4.2.3. Same Origin Policy
- 4.2.3.1. Same Origin Policy for the file domain
- 4.2.3.2. Same Origin Policy for Cookies
- 4.2.3.3. Flash/SilverLight cross domain
- 4.2.3.4. JSONP cross domain
- 4.2.3.5. Cross-Origin Scripting API Access
- 4.2.3.6. Cross-Origin Data Store Access
- 4.2.3.7. Common request headers
- 4.2.3.8. Common return headers
- 4.2.3.9. Defense Recommendations
- 4.2.4. CSP
- 4.2.5. XSS data sources
- 4.2.6. Sink
- 4.2.7. XSS Protection
- 4.2.8. WAF Bypass
- 4.2.9. Skills
- 4.2.10. Payload
- 4.2.10.1. Commonly used
- 4.2.10.2. Case Bypass
- 4.2.10.3. Various alert
- 4.2.10.4. Pseudo-protocols
- 4.2.10.5. Chrome XSS auditor bypass
- 4.2.10.6. Length restrictions
- 4.2.10.7. jquery sourceMappingURL
- 4.2.10.8. Image name
- 4.2.10.9. Expired payloads
- 4.2.10.10. css
- 4.2.10.11. markdown
- 4.2.10.12. iframe
- 4.2.10.13. form
- 4.2.10.14. meta
- 4.2.11. Persistence
- 4.2.12. Reference Links