AI, Data Science & Business Certificates from Google, IBM & Microsoft
Learn Excel & Financial Modeling the Way Finance Teams Actually Use Them
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore the vulnerabilities and security challenges of online WYSIWYG editors in this Black Hat conference talk. Discover how to break the top 25 online rich-text editors powering thousands of web applications, including popular ones like TinyMCE, Jive, Froala, and CKEditor. Learn about real-world XSS bypasses on major platforms such as Twitter, Yahoo Email, Amazon, GitHub, Magento, and CNET. After demonstrating these vulnerabilities, gain insights into a practical and effective sanitizer solution based on just 11 characters and 3 regular expressions. Understand how this sanitizer can protect against XSS attacks in various contexts, including HTML, attribute, script (including JSON), style, and URL.
Syllabus
Revisiting XSS Sanitization
Taught by
Black Hat