multi-layer-bypass

1 article
sort: new top best
clear filter
0 8/10

A detailed technical writeup on chaining eight XSS vulnerabilities at Airbnb by sequentially bypassing JSON encoding, XSS filters, WAF protection using null-byte injection, CSP rules, and Chrome's XSS auditor through the listing_frame embeddable endpoint. The exploitation leverages semicolon injection, null-byte WAF evasion, JSON encoder quirks, and CSP weaknesses.

Airbnb Ben Sadeghipour Brett Buerhaus HackerOne Chrome XSS Auditor
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details