Security Notes
search
Ctrlk
  • redhatWhoami
  • Pentestingchevron-right
    • WEP-Penchevron-right
      • Reconnaissance
      • Enumeration
      • OWSAP TOP 10chevron-right
        • A01 Broken Access Controlchevron-right
        • A02 Security Misconfigurationchevron-right
        • A03 Software Supply Chain Failureschevron-right
        • A04 Cryptographic Failureschevron-right
        • A05 Injectionchevron-right
        • A06 Insecure Designchevron-right
        • A07 Authentication Failureschevron-right
        • A08 Software or Data Integrity Failureschevron-right
          • mass assignment
          • PostMessage Vulnerabilitieschevron-right
            • PostMessage Vulnerabilities
            • Blocking main page to steal postmessage
            • Bypassing SOP with Iframes - part 1
            • Bypassing SOP with Iframes - part 2
            • Steal postmessage modifying iframe location
        • A09 Security Logging and Alerting Failureschevron-right
        • A10 Mishandling of Exceptional Conditions
      • JWT Hacking
      • Checklistschevron-right
    • API-Penchevron-right
    • NET-Penchevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Pentestingchevron-right
  2. WEP-Penchevron-right
  3. OWSAP TOP 10chevron-right
  4. A08 Software or Data Integrity Failures

PostMessage Vulnerabilities

PostMessage Vulnerabilitieschevron-rightBlocking main page to steal postmessagechevron-rightBypassing SOP with Iframes - part 1chevron-rightBypassing SOP with Iframes - part 2chevron-rightSteal postmessage modifying iframe locationchevron-right
Previousmass assignmentchevron-leftNextPostMessage Vulnerabilitieschevron-right

Last updated 1 year ago