Case D396FE · Web AppSec · L2 Practitioner
Cross-Site Scripting (XSS)
Practise as: Explain it · Interview · Deep dive
Interview questionExplain the difference between stored, reflected and DOM-based XSS, and what actually stops each one.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- XSS runs attacker JavaScript in the victim origin, so it can read the DOM, act as the user, and steal non-HttpOnly tokens
- Stored: payload persisted server-side; reflected: echoed from the request; DOM: client JS writes a source into a sink
- Fix is context-aware output encoding (HTML body, attribute, JS, URL differ); frameworks auto-escape by default
- Dangerous sinks bypass that: innerHTML, dangerouslySetInnerHTML, v-html, eval, javascript: URLs in href
- Mitigate impact with strict nonce/hash-based CSP, HttpOnly cookies, and Trusted Types for DOM sinks
If the interviewer pushes back
- Why does an HttpOnly cookie not fully neutralize XSS impact?
- How can a CSP with script-src self still be bypassed, e.g. via JSONP endpoints or uploaded files?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.