I know XSS is dying due to CORS and DLL injection is mooted by ALSR, that API's are usually authenticated and authorized, but damn...
I wish there was a more collective place to showcase modern exploits, they just hit nice in the feelies.
I know XSS is dying due to CORS and DLL injection is mooted by ALSR, that API's are usually authenticated and authorized, but damn...
I wish there was a more collective place to showcase modern exploits, they just hit nice in the feelies.
CORS isn't related to XSS. CORS actually isn't a security protection at all. It's a way for web apps to explicitly disable standard protections that browsers apply to enforce same origin policy.
You might be thinking of Content Security Policy (CSP).[0] That's the most effective protection I'm aware of for XSS, but it's not very widely used because so few JavaScript libraries are compatible with it.
>so few JavaScript libraries are compatible with it.
is this because of the 'eval' function specifically, or is there other reasons?
The other gotcha is that with a secure CSP policy, you can no longer do things like <button onclick="handleClick"> because that's inline JS, so that's kind of a bummer.
[0] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
I see why; in return to libc, which is prevented by ASLR, you are injecting the control of flow into the middle of a DLL(that DLL is libc). The terminology is a little confusing.