0 of 0 steps completed

Eight phases, from fundamentals to high-impact chaining. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Work the phases in order, and spend the most time in Phase 2 and Phase 5.

Phase 1: XSS Fundamentals

Step 1.1 What is XSS and why it matters
Step 1.2 Reflected, stored, and DOM XSS
Step 1.3 Sources and sinks in DOM XSS

Phase 2: DOM XSS Deep Dive

Step 2.1 Advanced DOM XSS sources and sinks
Step 2.2 DOM Clobbering
Step 2.3 Mutation XSS (mXSS)
Step 2.4 DOMPurify bypasses

Phase 3: Tooling and Programming

Step 3.1 JavaScript for DOM XSS
Step 3.2 DOM XSS scanners and tools
Step 3.3 Fuzzing and research

Phase 4: Labs and Practice

Step 4.1 PortSwigger Web Security Academy
Step 4.2 Hack The Box Academy and machines
Step 4.3 CTF and bug bounty practice

Phase 5: Chaining XSS for High Impact

Step 5.1 Chaining basics
Step 5.2 High-impact chains
  • HackerOneHacktivity, XSS to account takeover reports
  • BlogSelf-XSS in a payments flow to full account takeover (study the cross-origin and SDK abuse steps)
  • BlogChaining a DOM XSS sink, WAF bypass, and cross-origin smuggling into one-click account takeover
Step 5.3 Bug bounty targets: Meta, Google, Epic Games

Phase 6: Prevention and Defense

Step 6.1 Prevention cheat sheets
Step 6.2 Secure coding

Phase 7: Books, Podcasts, and Videos

Step 7.1 Essential books
  • BookJavaScript for Hackers, Gareth Heyes
  • BookThe Tangled Web, Michal Zalewski
  • BookThe Web Application Hacker's Handbook, Chapter 12, Stuttard and Pinto
Step 7.2 Podcasts
Step 7.3 YouTube playlists and channels

Phase 8: Exam Preparation and Career

Step 8.1 CWES and CWEE XSS topics
Step 8.2 Bug bounty workflow