Перейти к содержимому

Reflected XSS with AngularJS Sandbox Escape Without Strings

z3nsh3ll

0:00 / 0:00

Reflected XSS with AngularJS Sandbox Escape Without Strings

6 253 просмотра · 3 года назад
z3nsh3ll
10,8 тыс. подписчиков
6 253 просмотра · 3 года назад
In this video we solve the portswigger lab with the title 'Reflected XSS with AngularJS Sandbox Escape Without Strings' We explore the solution in depth and provide an explanation regarding the angularJS sandbox and sandbox escapes. We also briefly consider the history of the angularJS sandbox. 00:00 Intro 01:04 AngularJS recap 02:21 Arbitrary search string 05:06 AngularJS $parse 07:20 Injection into the URL 09:12 Testing for injection vulnerabilities 11:55 Alert() injection test 13:34 Intro to AngularJS Sandbox 15:03 Intro to sandbox escapes 17:27 Removal of AngularJS sandbox 18:29 Gareth Heyes sandbox writeup 19:17 AngularJS v1.4.4 specific exploit 22:05 isIdent sandbox function 24:16 Analysing the exploit 26:44 Backdooring strings 28:49 AngularJS orderBy 31:48 Summary and solving the lab