Webapp 25
- Bypass Payment Process
- Account Takeover
- hop-by-hop headers
- 2FA/MFA/OTP Bypass
- XSS in Markdown
- WebAssembly linear memory corruption to DOM XSS (template overwrite)
- Steal Info JS
- SOME - Same Origin Method Execution
- Sniff Leak
- Shadow DOM
- Server Side XSS (Dynamic PDF)
- PDF Injection
- Misc JS Tricks & Relevant Info
- JS Hoisting
- Integer Overflow (Web Applications)
- Iframes in XSS, CSP and SOP
- DOM XSS
- DOM Invader
- Dom Clobbering
- Debugging Client Side JS
- Chrome Cache to XSS
- Abusing Service Workers
- PDF Upload
- PDF Upload - XXE and CORS bypass
- Open Redirect