daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

debugging-client-side-js.md (2622B)


      1 ---
      2 title: "Debugging Client-Side JavaScript"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/debugging-client-side-js.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/debugging-client-side-js.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Debugging Client-Side JavaScript
     14 
     15 Client-side JavaScript debugging can become repetitive when navigation or parameter changes reload the page and invalidate temporary debugging state.
     16 
     17 ## `debugger;`
     18 
     19 When developer tools are open, a `debugger;` statement pauses execution at that point unless breakpoints are disabled. Adding the statement to a persistent local copy is one way to keep the pause point across reloads.<sup>[[1]](#references)</sup>
     20 
     21 ## Overrides
     22 
     23 Chrome DevTools Local Overrides stores a local replacement for a network resource and serves that replacement on subsequent page loads.<sup>[[2]](#references)</sup>
     24 
     25 1. Open **DevTools > Sources > Overrides**.
     26 2. Select an empty local folder and allow DevTools to access it.
     27 3. In the **Page** tree, right-click the target script and select **Override content** or **Save for overrides**, depending on the Chrome version.
     28 4. Add `debugger;`, save the file, and reload the page.
     29 
     30 ![Selecting a JavaScript file in the Sources panel and saving it as a local override](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28742%29.png)
     31 
     32 The saved local copy now replaces the matching network resource while overrides are enabled. Changes therefore persist across reloads, but they affect only your local browser profile.<sup>[[2]](#references)</sup>
     33 
     34 ![A locally overridden JavaScript file containing a debugger statement](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28594%29.png)
     35 
     36 The XSS challenge walkthrough in reference 3 demonstrates this `debugger;` and Local Overrides workflow during a practical client-side analysis.<sup>[[3]](#references)</sup>
     37 
     38 ## References
     39 
     40 - [1] [Chrome for Developers - JavaScript debugging reference](https://developer.chrome.com/docs/devtools/javascript/reference)
     41 - [2] [Chrome for Developers - Override web content and HTTP response headers locally](https://developer.chrome.com/docs/devtools/overrides/)
     42 - [3] [YouTube - 4 hackers, one XSS challenge](https://www.youtube.com/watch?v=BW_-RCo9lo8&t=1529s)