Back to directory
WRITEUP #5960

Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper

XSSDOM XSSUniversal XSSClickjackingBrowser extension hacking
by@IAmMandatory(Matthew Bryant)
Program
-
Published
Jun 8, 2018
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://thehackerblog.com/steam-fire-and-paste-a-story-of-uxss-via-dom-xss-clickjacking-in-steam-inventory-helper/index.html
RELATED WRITEUPS
Universal Code Execution by Chaining Messages in Browser Extensions
XSSUniversal XSS
Lessons Learned From Exposing Unusual XSS Vulnerabilities
XSSDOM XSS
Self-XSS to ATO via Site Features
XSSSelf-XSS
How 100% Manual Hacking (Without Even Kali And Burp) Led To 2 Medium Vulnerabilities On YesWeHack
XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS

Built with ❤️ by Shubham Rawat