weizman / shield

Shield your DOM against clobbering attacks effortlessly
https://weizmangal.com/shield/
MIT License
3 stars 0 forks source link

Stress test found some bypasses #12

Open weizman opened 2 months ago

weizman commented 2 months ago

Used @SoheilKhodayari's fantastic research @ domclob.xyz to stress test shield, and while it performed rather well, there were 10-20 tests that bypassed shield to further investigate (see https://weizmangal.com/shield/robust.html)

weizman commented 2 months ago

Screenshot 2024-09-16 at 12 32 50