Uploaded October 2020 | Updated September 2026, 2 weeks ago
In the second part we are building on top of what we have learned. We figure out how to craft something special out of a very limited script gadget. Eventually we can use it to leak the secret notes ID and notes content.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-xss/xss-ctf-challenges
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Part 1: youtube.com/watch?v=dZXaQKEE3A8
Challenge: capturetheflag.withgoogle.com/challenges/web-littlethings
Pasteurize: youtube.com/watch?v=Tw7ucd2lKBk
CHAPTERS
00:00 - Recap Part 1
00:20 - Start of the Attack Chain
00:54 - Control the Theme Callback
02:29 - Prior JSONP Capability Research
04:40 - innerHTML Breakthrough
06:13 - Content Security Policy Fail
07:19 - iframe CSP Bypass
08:31 - The Solution
10:09 - Chaining Three Gadgets
11:34 - Researching Cool XSS Techniques
12:00 - Solving the Challenge
13:25 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#WebSecurity #CTF #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
In the second part we are building on top of what we have learned. We figure out how to craft something special out of a very limited script gadget. Eventually we can use it to leak the secret notes ID and notes content.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-xss/xss-ctf-challenges
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Part 1: youtube.com/watch?v=dZXaQKEE3A8
Challenge: capturetheflag.withgoogle.com/challenges/web-littlethings
Pasteurize: youtube.com/watch?v=Tw7ucd2lKBk
CHAPTERS
00:00 - Recap Part 1
00:20 - Start of the Attack Chain
00:54 - Control the Theme Callback
02:29 - Prior JSONP Capability Research
04:40 - innerHTML Breakthrough
06:13 - Content Security Policy Fail
07:19 - iframe CSP Bypass
08:31 - The Solution
10:09 - Chaining Three Gadgets
11:34 - Researching Cool XSS Techniques
12:00 - Solving the Challenge
13:25 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#WebSecurity #CTF #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










