Uploaded September 2022 | Updated September 2026, 2 weeks ago
In August 1996, Internet Explorer joined the JavaScript security scene with JScript. This history episode follows early browser bugs from roughly 1996–2000 to explain what researchers came to call Universal Cross-Site Scripting (UXSS).
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-history-xss/history-of-xss
Join the Hextree Discord: discord.gg/xgQpCQCpvy
RESOURCES
Jabadoo Security Hole in Explorer 4.0: seclists.org/bugtraq/1997/Oct/85
Aleph One on Jabadoo: seclists.org/bugtraq/1997/Oct/87
Georgi Guninski "IE can read local files": seclists.org/bugtraq/1998/Sep/47
Georgi's resume: https://j.ludost.net/resumegg.pdf
"Cross-frame security policy": seclists.org/bugtraq/2000/Jan/93
RELATED EPISODES
Episode 01 - First JS Bug: youtube.com/watch?v=bSJm8-zJTzQ
Episode 02 - Three JS Security Researchers: youtube.com/watch?v=VtcA58555lY
CHAPTERS
00:00 - Intro to the "Age of Universal XSS"
01:16 - JavaScript Security in Netscape 1996
01:52 - JScript Vulnerability in Internet Explorer
03:38 - Georgi Guninski: IE can read local files (1998)
05:12 - Who is Georgi Guninski?
06:36 - Georgi Guninski: IE 5 circumventing cross-frame security policy
09:41 - David Ross from Microsoft about Georgi
10:16 - "Cross-Frame" Browser Bugs
11:17 - Universal Cross-Site Scripting
12:15 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#WebSecurity #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
In August 1996, Internet Explorer joined the JavaScript security scene with JScript. This history episode follows early browser bugs from roughly 1996–2000 to explain what researchers came to call Universal Cross-Site Scripting (UXSS).
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-history-xss/history-of-xss
Join the Hextree Discord: discord.gg/xgQpCQCpvy
RESOURCES
Jabadoo Security Hole in Explorer 4.0: seclists.org/bugtraq/1997/Oct/85
Aleph One on Jabadoo: seclists.org/bugtraq/1997/Oct/87
Georgi Guninski "IE can read local files": seclists.org/bugtraq/1998/Sep/47
Georgi's resume: https://j.ludost.net/resumegg.pdf
"Cross-frame security policy": seclists.org/bugtraq/2000/Jan/93
RELATED EPISODES
Episode 01 - First JS Bug: youtube.com/watch?v=bSJm8-zJTzQ
Episode 02 - Three JS Security Researchers: youtube.com/watch?v=VtcA58555lY
CHAPTERS
00:00 - Intro to the "Age of Universal XSS"
01:16 - JavaScript Security in Netscape 1996
01:52 - JScript Vulnerability in Internet Explorer
03:38 - Georgi Guninski: IE can read local files (1998)
05:12 - Who is Georgi Guninski?
06:36 - Georgi Guninski: IE 5 circumventing cross-frame security policy
09:41 - David Ross from Microsoft about Georgi
10:16 - "Cross-Frame" Browser Bugs
11:17 - Universal Cross-Site Scripting
12:15 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#WebSecurity #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










