payload-construction

1 article
sort: new top best
clear filter
0 8/10

Technical writeup on bypassing uppercase character filters in URL-based XSS vulnerabilities using JSFuck obfuscation techniques. The authors demonstrate constructing a complete alphabet from JavaScript primitive values and achieving arbitrary code execution with jQuery's getScript to escalate a Low severity XSS to Critical by loading external malicious scripts.

jsfuck.com Martin Kleppe Burp Suite HackerOne WordPress
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details