TG Telegram Group & Channel
R_bugbounty | United States America (US)
Create: Update:

I'm curious about XSS filtering

Hi everyone. I'm a bugbounty novice. I'm currently spending a lot of time manually looking for bugs. First of all, I'd like to say that I've already studied the concept, type, etc. of XSS. But I'm asking you a question because I don't think I'm familiar with how XSS is being filtered, etc.

When I type in the payload to find the XSS on the site, they're filtered with high probability, and from what I've studied, they're called sanitizing and escapes. I checked that contents like <, > or "script" are filtered or these are treated as strings.


So, I was wondering implementing XSS is which of the two, or both:

1) Whether you're looking for a bypass beyond this filtering, or

2) if you're trying to inject XSS on a site that doesn't use this filtering.

If it's number one, filtering techniques are advanced for each applied site, and it seems to be almost similar. Do you have any tips in this regard? I've looked into the related content and it's too hard for me. Please give me some advise on this.




https://redd.it/1cezl8p
@r_bugbounty

I'm curious about XSS filtering

Hi everyone. I'm a bugbounty novice. I'm currently spending a lot of time manually looking for bugs. First of all, I'd like to say that I've already studied the concept, type, etc. of XSS. But I'm asking you a question because I don't think I'm familiar with how XSS is being filtered, etc.

When I type in the payload to find the XSS on the site, they're filtered with high probability, and from what I've studied, they're called sanitizing and escapes. I checked that contents like <, > or "script" are filtered or these are treated as strings.


So, I was wondering implementing XSS is which of the two, or both:

1) Whether you're looking for a bypass beyond this filtering, or

2) if you're trying to inject XSS on a site that doesn't use this filtering.

If it's number one, filtering techniques are advanced for each applied site, and it seems to be almost similar. Do you have any tips in this regard? I've looked into the related content and it's too hard for me. Please give me some advise on this.




https://redd.it/1cezl8p
@r_bugbounty


>>Click here to continue<<

R_bugbounty






Share with your best friend
VIEW MORE

United States America Popular Telegram Group (US)