Open cardosec

Case D396FE · Web AppSec · L2 Practitioner

Cross-Site Scripting (XSS)

Practise as: Explain it · Interview · Deep dive

Interview questionExplain the difference between stored, reflected and DOM-based XSS, and what actually stops each one.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. XSS runs attacker JavaScript in the victim origin, so it can read the DOM, act as the user, and steal non-HttpOnly tokens
  2. Stored: payload persisted server-side; reflected: echoed from the request; DOM: client JS writes a source into a sink
  3. Fix is context-aware output encoding (HTML body, attribute, JS, URL differ); frameworks auto-escape by default
  4. Dangerous sinks bypass that: innerHTML, dangerouslySetInnerHTML, v-html, eval, javascript: URLs in href
  5. Mitigate impact with strict nonce/hash-based CSP, HttpOnly cookies, and Trusted Types for DOM sinks

If the interviewer pushes back

  • Why does an HttpOnly cookie not fully neutralize XSS impact?
  • How can a CSP with script-src self still be bypassed, e.g. via JSONP endpoints or uploaded files?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.