postMessage()

Bookmarked!

This exercise covers how insecure calls to the JavaScript function postMessage() can be used to leak sensitive information

PRO Medium < 1 Hr. 1298 Orange Badge
Course

This course teaches you how to exploit vulnerabilities in applications using the <code>postMessage</code> method without setting a destination. By understanding and leveraging this issue, you will learn how to get an administrator to leak confidential information to your server.

Injection Authentication Authorisation Client Side
Full course content 2 videos Common mistakes

This lab is free this month. Register to start hacking.

Register free