Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF

Detectify

Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF

Detectify’s knowledge advisor Frans Rosén wrote a blog post for the Bugcrowd about using a Braun Shaver to Bypass XSS Audit and WAF. Bugcrowd is a crowdsourced cybersecurity platform where hackers take part in bug bounty programs, helping companies fix vulnerabilities.

Read more at the Bugcrowd blog for a write-up featuring an XSS exploit and a personal hygiene product.

 

braun-html

 

 

Check out more content

Account hijacking using “dirty dancing” in sign-in OAuth-flows

TL;DR Combining response-type switching, invalid state and redirect-uri quirks using OAuth, with third-party javascript-inclusions has multiple vulnerable scenarios where authorization codes or tokens could leak to an attacker. This could be used in attacks for single-click account takeovers. Frans Rosén, Security Advisor at Detectify goes through three different scenarios found in the wild below.