XSS Mastery Roadmap: DOM XSS, mXSS, Clobbering, and Chaining
0 of 0 steps completed
Eight phases, from fundamentals to high-impact chaining. Each step has a checkbox and a list of resources. Tick steps as you finish them. Progress is saved in this browser. Work the phases in order, and spend the most time in Phase 2 and Phase 5.
Phase 1: XSS Fundamentals
Step 1.1 What is XSS and why it matters
- BookThe Web Application Hacker's Handbook, Chapter 12 (Attacking Users: Cross-Site Scripting), Stuttard and Pinto
- HTB AcademyCross-Site Scripting (XSS)
- PortSwiggerCross-site scripting (all levels)
- DocOWASP Cross Site Scripting Prevention Cheat Sheet
- YouTubeSTÖK, XSS content
Step 1.2 Reflected, stored, and DOM XSS
- HTB AcademyCross-Site Scripting (XSS), all three types
- PortSwiggerReflected XSS, Stored XSS, DOM-based XSS
- HackTricksXSS (Cross Site Scripting)
- PayloadsPayloadsAllTheThings, XSS Injection
Step 1.3 Sources and sinks in DOM XSS
- BookJavaScript for Hackers, Gareth Heyes
- PortSwiggerDOM-based vulnerabilities, sources and sinks (innerHTML, document.write, jQuery selector sinks)
- ToolDOM Invader, source and sink tracing
Phase 2: DOM XSS Deep Dive
Step 2.1 Advanced DOM XSS sources and sinks
- BookJavaScript for Hackers, Gareth Heyes (DOM chapters)
- PortSwiggerDOM XSS using web messages
- PortSwiggerClient-side prototype pollution to DOM XSS
- ToolDOM Invader, web message and prototype pollution testing
Step 2.2 DOM Clobbering
- HackTricksDOM Clobbering
- PayloadsPayloadsAllTheThings, DOM clobbering notes
- PaperThe DOMino Effect: Detecting and Exploiting DOM Clobbering Gadgets (USENIX Security)
- HTB AcademyJavaScript Deobfuscation
Step 2.3 Mutation XSS (mXSS)
- PapermXSS Attacks: Attacking well-secured Web-Applications, Heiderich et al.
- BlogGareth Heyes, Bypassing DOMPurify again with mutation XSS
- BlogMichał Bentkowski, Mutation XSS via namespace confusion
- TalkMario Heiderich, The innerHTML Apocalypse (how mXSS attacks work)
Step 2.4 DOMPurify bypasses
Phase 3: Tooling and Programming
Step 3.1 JavaScript for DOM XSS
- BookJavaScript for Hackers, Gareth Heyes
- YouTubeLiveOverflow, JavaScript and web exploitation
- GitHubterjanq/Tiny-XSS-Payloads
Step 3.2 DOM XSS scanners and tools
Step 3.3 Fuzzing and research
- Paper25 Million Flows Later: Large-scale Detection of DOM-based XSS (CCS)
- PayloadsPayloadsAllTheThings, XSS filter bypass lists
- GitHubterjanq/Tiny-XSS-Payloads, compact payload research
Phase 4: Labs and Practice
Step 4.1 PortSwigger Web Security Academy
- PortSwiggerAll XSS labs (apprentice, practitioner, expert)
- PortSwiggerDOM-based vulnerabilities labs
- PortSwiggerPrototype pollution labs
- PortSwiggerWeb cache poisoning labs
Step 4.2 Hack The Box Academy and machines
- HTB AcademyCross-Site Scripting (XSS) module
- HTB AcademyJavaScript Deobfuscation
- HTB MachineWeb machines with client-side injection (check retired machine list for XSS)
Step 4.3 CTF and bug bounty practice
Phase 5: Chaining XSS for High Impact
Step 5.1 Chaining basics
Step 5.2 High-impact chains
- HackerOneHacktivity, XSS to account takeover reports
- BlogSelf-XSS in a payments flow to full account takeover (study the cross-origin and SDK abuse steps)
- BlogChaining a DOM XSS sink, WAF bypass, and cross-origin smuggling into one-click account takeover
Step 5.3 Bug bounty targets: Meta, Google, Epic Games
Phase 6: Prevention and Defense
Step 6.1 Prevention cheat sheets
Step 6.2 Secure coding
- BookThe Tangled Web, Michal Zalewski
- BookWeb Security for Developers, Malcolm McDonald (XSS chapters)
- GitHubcure53/DOMPurify, safe sanitization in practice
Phase 7: Books, Podcasts, and Videos
Step 7.1 Essential books
- BookJavaScript for Hackers, Gareth Heyes
- BookThe Tangled Web, Michal Zalewski
- BookThe Web Application Hacker's Handbook, Chapter 12, Stuttard and Pinto
Step 7.2 Podcasts
Step 7.3 YouTube playlists and channels
- YouTubePwnFunction, XSS explained
- YouTubeLiveOverflow, JavaScript for hackers
- YouTubeSTÖK, NahamSec, InsiderPhD
- YouTubePortSwigger, official lab walkthroughs
Phase 8: Exam Preparation and Career
Step 8.1 CWES and CWEE XSS topics
- HTB AcademyCWES path XSS modules
- HTB AcademyCWEE path advanced client-side modules
- PortSwiggerXSS labs as timed exam practice