<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CSP on Taha Draidia</title><link>https://tahadraidia.com/tags/csp/</link><description>Recent content in CSP on Taha Draidia</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 17 Jan 2019 00:00:00 +0000</lastBuildDate><atom:link href="https://tahadraidia.com/tags/csp/index.xml" rel="self" type="application/rss+xml"/><item><title>Bypass Content Security Policy framing restriction rule - OLX</title><link>https://tahadraidia.com/posts/bypass-csp-framing-restriction-rule-olx/</link><pubDate>Thu, 17 Jan 2019 00:00:00 +0000</pubDate><guid>https://tahadraidia.com/posts/bypass-csp-framing-restriction-rule-olx/</guid><description>It&amp;rsquo;s been a while since my last post. Today I decided to share with you a bug I found on a public bug bounty program on HackerOne. You can find the original report here.
This post is about a misconfiguration in CSP rule that leaves the website vulnerable to UI redressing aka clickjacking. This attack is widly used by scammer and spammers to trick users.
After some recon on olx.co.za and olx.</description></item></channel></rss>