tech/webdev magazine

May 5, 2016

Adapting AngularJS Payloads to Exploit Real World Applications

Thursday, May 05, 2016 Teklinks

Every experienced pentester knows there is a lot more to XSS than .. - filtering, encoding, browser-quirks and WAFs all team up to keep things interesting. AngularJS Template Injection is no different. In this post, we will examine how we adapted template injection payloads to bypass filtering and encoding and exploit Piwik and Uber.

Full article