Course
This course covers the exploitation of an application using <code>addEventListener()</code> without verifying the origin of the message, making it vulnerable to Cross-Site Scripting (XSS). You'll learn how to convert a self-XSS into an XSS using an iframe and postMessage().
Skills covered
This lab is free this month. Register to start hacking.
Register free