✨
AppSec & Pentest
Ctrlk
  • AppSec Book
  • Intro
  • PII: Персональные данные
  • Поисковые движки
  • Построение модели угроз / анализ угроз
  • Платформы оркестрации, автоматизации пентеста
  • Audit and Compliance
  • Methodologies
  • peoples & blogs
  • Базы уязвимостей
  • Pentest IDE
  • Payloads & Wordlists
    • Генерация wordlists
    • Payloads
    • Расширения файлов, которые можно искать
    • Bypass Something
  • AppSec / WEB
    • Common
    • Automated WebApp Pentest
    • Server-Side Vulnerabilities
    • Client-Side Vulnerabilities
      • Vulnerabilities
      • CSRF
      • CRLF
      • XSS
        • Description
        • Attacks
          • Exploiting XSS
          • GTM (and other TMS) XSS
          • Через SVG
          • DOM-based vulnerabilities
            • About
            • DOM-based XSS
            • DOM-based open redirect
            • DOM Clobbering
          • Local File Read via HTML injection in PDF
          • RCE in DOMPDF
          • [висячая разметка] Dangling markup injection
          • String.prototype.replace
          • CSS injection
          • jQuery XSS
          • AngularJS Sandbox Escape
        • Gadgets
        • Tools
        • Cheat Sheets
        • Papers
      • Prototype Pollution Attack
      • Client-Side & Client-Server Communications
      • Eval-based Injections
      • Serialization
      • Incorrect work with location
      • Clickjacking (UI redressing)
    • Technics
    • SSDLC
    • DevSecOps
    • Browser PWN
    • Вопросы
    • ЯП
    • Books & Papers
    • Tools
  • Technologies
    • WEB
    • Покупка SIM-карт и номеров
    • Banks & Payments
    • Программы лояльности
    • Digital Rights Management (DRM)
    • ELK — Elasticsearch, Logstash, Kibana
    • 1C
    • CI/CD
    • SCM
    • Honeypots
    • ChatGPT
  • Learning
    • Компетенции
    • Материалы SANS & Offensive Security
    • Просто норм материалы/gitbooks по пентесту вцелом...
    • Platforms & Playground Labs
    • Бумажная ИБ
  • Bug Bounty
    • Notes
    • Browser Plugins
    • Cheat Sheets
    • Платформы
    • Specific tools
  • Hardware/IoT
    • Tools
    • Training
    • Papers & Books
Powered by GitBook
On this page
  1. AppSec / WEB
  2. Client-Side Vulnerabilities
  3. XSS
  4. Attacks

DOM-based vulnerabilities

AboutDOM-based XSSDOM-based open redirectDOM Clobbering
PreviousЧерез SVGNextAbout

Last updated 3 years ago

Was this helpful?

Was this helpful?