xss-dom - DOM-Based XSS Exploitation Guide
Guide DOM-based XSS exploitation during authorized penetration testing.
Tags
Updated: 2026-09-24Typical Inputs
What this skill does
- Assess target page
- Identify sources
- Identify sinks
- Trace data flow
- Demonstrate impact
- Escalate or pivot
Inputs
- Target page URL
- Suspected source
- Suspected sink
- Engagement state
Outputs
- Screen activation log
- Evidence files in engagement directory
- Return summary
Requirements
- Explicit written authorization
- Access to target page JavaScript
- Browser tools with JavaScript execution
