Portswigger Web Academy - DOM XSS - Lab Walkthroughs @Tib3rius
Portswigger Web Academy - DOM XSS - Lab Walkthroughs  @Tib3rius
Uploaded July 2023 | Updated September 2026, 3 hours ago
In this video, Tib3rius completes three DOM XSS labs from Portswigger Web Academy.

The labs completed are as follows:

DOM XSS in jQuery anchor href attribute sink using location.search source: portswigger.net/web-security/cross-site-scripting/dom-based/lab-jquery-href-attribute-sink
DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded: portswigger.net/web-security/cross-site-scripting/dom-based/lab-angularjs-expression
Reflected DOM XSS: portswigger.net/web-security/cross-site-scripting/dom-based/lab-dom-xss-reflected

0:00 - Intro
0:20 - Starting Lab: DOM XSS in jQuery anchor href attribute sink using location.search source
1:02 - DOM Invader overview.
2:40 - Using DOM Invader to find the injection point.
4:18 - Brief explanation of how DOM XSS is different to (regular) XSS.
5:38 - Reviewing the vulnerable JavaScript code which allows the DOM XSS to occur.
6:23 - Starting Lab: DOM XSS in AngularJS expression with angle brackets and double quotes HTML-encoded
7:51 - Triggering the CSTI with a common payload.
10:49 - For the memes.
11:25 - Using Portswigger's XSS Cheatsheet to find a payload.
13:02 - History lesson on Angular JS sandbox escapes.
17:19 - Triggering an alert box with a CSTI payload.
17:49 - Starting Lab: Reflected DOM XSS
18:39 - Manually inputting the DOM Invader canary and finding a sink.
19:48 - Reviewing the vulnerable JavaScript code to figure out an exploit.
21:56 - Creating a payload by exploiting the lack of backslash escaping!
23:06 - Outro

Twitter: twitter.com/0xTib3rius
Twitch: twitch.tv/0xTib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
Threads: threads.net/@0xtib3rius
LinkedIn: linkedin.com/in/tib3rius
Facebook: facebook.com/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
Portswigger Web Academy - DOM XSS - Lab WalkthroughsWeb App Wednesday!Revealing the TRUTH about the JWT abbreviation! #techtok #cybersecurity #technology #appsecReading Mean Comments (Tech Edition 2023) Part 3 #comedy #technology #infosec #cybersecurity #techGetting Into Cybersecurity - An Interview with @Tracketpacer (Trailer) #cybersecurity #technologyOR-Based SQL Injection Without the Dangers! Safe Alternatives to OR 1=1!Cyber Mentoring Monday!Web App Wednesday!Pentesting War Stories with Andy SwiftWeb App Wednesday - HackingHub SQLi Labs!Portswigger Web Academy - HTTP Request Smuggling - Explanation & Lab WalkthroughWeb App Wednesday!
Tib3rius |

Portswigger Web Academy - DOM XSS - Lab Walkthroughs

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER