Reflected XSS with AngularJS Sandbox Escape Without Strings
z3nsh3ll
0:00 / 0:00
Reflected XSS with AngularJS Sandbox Escape Without Strings
6 253 просмотра · 3 года назад
z3nsh3ll
10,8 тыс. подписчиков
6 253 просмотра · 3 года назад
In this video we solve the portswigger lab with the title 'Reflected XSS with AngularJS Sandbox Escape Without Strings'
We explore the solution in depth and provide an explanation regarding the angularJS sandbox and sandbox escapes. We also briefly consider the history of the angularJS sandbox.
00:00 Intro
01:04 AngularJS recap
02:21 Arbitrary search string
05:06 AngularJS $parse
07:20 Injection into the URL
09:12 Testing for injection vulnerabilities
11:55 Alert() injection test
13:34 Intro to AngularJS Sandbox
15:03 Intro to sandbox escapes
17:27 Removal of AngularJS sandbox
18:29 Gareth Heyes sandbox writeup
19:17 AngularJS v1.4.4 specific exploit
22:05 isIdent sandbox function
24:16 Analysing the exploit
26:44 Backdooring strings
28:49 AngularJS orderBy
31:48 Summary and solving the lab