dom-invader.md (7935B)
1 --- 2 title: "DOM Invader" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/dom-invader.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/dom-invader.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # DOM Invader 14 15 ## DOM Invader 16 17 DOM Invader is a browser tool installed in **Burp Suite's built-in Chromium browser**. It assists in **detecting DOM XSS and other client-side vulnerabilities** (prototype pollution, DOM clobbering, etc.) by automatically **instrumenting JavaScript sources and sinks**. The extension ships with Burp and only needs to be enabled.<sup>[[1]](#references)</sup> 18 19 DOM Invader adds a tab to the browser’s DevTools panel that lets you: 20 21 1. **Identify controllable sinks** in real time, including context (attribute, HTML, URL, JS) and applied sanitization. 22 2. **Log, edit and resend `postMessage()` web-messages**, or let the extension mutate them automatically. 23 3. **Detect client-side prototype-pollution sources and scan for gadget→sink chains**, generating PoCs on-the-fly. 24 4. **Find DOM clobbering vectors** (e.g. `id` / `name` collisions that overwrite global variables). 25 5. **Fine-tune behaviour** via a rich Settings UI (custom canary, auto-injection, redirect blocking, source/sink lists, etc.). 26 27 --- 28 29 ### 1. Enable it 30 31 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281129%29.png" alt=""><figcaption></figcaption></figure> 32 33 1. Open **Proxy ➜ Intercept ➜ Open Browser** (Burp’s embedded browser). 34 2. Click the **Burp Suite** logo (top-right). If it’s hidden, click the jigsaw-piece first. 35 3. In **DOM Invader** tab, toggle **Enable DOM Invader** ON and press **Reload**. 36 4. Open DevTools ( `F12` / Right-click ➜ Inspect ) and dock it. A new **DOM Invader** panel appears. 37 38 > Burp remembers the state per profile. Disable it under *Settings ➜ Tools ➜ Burp’s browser ➜ Store settings...* if required.<sup>[[2]](#references)</sup> 39 40 ### 2. Inject a Canary 41 42 A **canary** is a random marker string (e.g. `xh9XKYlV`) that DOM Invader tracks. You can:<sup>[[3]](#references)</sup> 43 44 * **Copy** it and manually inject it in parameters, forms, Web-Socket frames, web-messages, etc. 45 * Use **Inject URL params / Inject forms** buttons to open a new tab where the canary is appended to every query key/value or form field automatically. 46 * Search for an **empty canary** to reveal all sinks regardless of exploitability (great for reconnaissance). 47 48 #### Custom canary (2025+) 49 50 Burp 2024.12 introduced **Canary settings** (Burp-logo ➜ DOM Invader ➜ Canary). You can:<sup>[[7]](#references)</sup> 51 52 * **Randomize** or set a **custom string** (helpful for multi-tab testing or when the default value appears naturally on the page). 53 * **Copy** the value to clipboard. 54 * Changes require **Reload**. 55 56 --- 57 58 ### 3. Web-messages (`postMessage`) 59 60 The **Messages** sub-tab records every `window.postMessage()` call, showing `origin`, `source`, and `data` usage.<sup>[[4]](#references)</sup> 61 62 • **Modify & resend**: double-click a message, edit `data`, and press **Send** (Burp Repeater-like). 63 64 • **Auto-fuzz**: enable **Postmessage interception ➜ Auto-mutate** in settings to let DOM Invader generate canary-based payloads and replay them to the handler. 65 66 Field meaning recap: 67 68 * **origin** – whether the handler validates `event.origin`. 69 * **data** – payload location. If unused, the sink is irrelevant. 70 * **source** – iframe / window reference validation; often weaker than strict‐origin checking. 71 72 --- 73 74 ### 4. Prototype Pollution 75 76 Enable under **Settings ➜ Attack types ➜ Prototype pollution**.<sup>[[5]](#references)</sup> 77 78 Workflow: 79 80 1. **Browse** – DOM Invader flags pollution **sources** (`__proto__`, `constructor`, `prototype`) found in URL/query/hash or JSON web-messages. 81 2. **Test** – clicks *Test* to open a PoC tab where `Object.prototype.testproperty` should exist: 82 83 ```javascript 84 let obj = {}; 85 console.log(obj.testproperty); // ➜ 'DOM_INVADER_PP_POC' 86 ``` 87 3. **Scan for gadgets** – DOM Invader bruteforces property names and tracks whether any end up in dangerous sinks (e.g. `innerHTML`). 88 4. **Exploit** – when a gadget-sink chain is found an *Exploit* button appears that chains source + gadget + sink to trigger alert. 89 90 Advanced settings (cog icon): 91 92 * **Remove CSP / X-Frame-Options** to keep iframes workable during gadget scanning. 93 * **Scan techniques in separate frames** to avoid `__proto__` vs `constructor` interference. 94 * **Disable techniques** individually for fragile apps. 95 96 --- 97 98 ### 5. DOM Clobbering 99 100 Toggle **Attack types ➜ DOM clobbering**. DOM Invader monitors dynamically created elements whose `id`/`name` attributes collide with global variables or form objects (`<input name="location">` → clobbers `window.location`). An entry is produced whenever user-controlled markup leads to variable replacement.<sup>[[6]](#references)</sup> 101 102 --- 103 104 ## 6. Settings Overview (2025) 105 106 DOM Invader is now split into **Main / Attack Types / Misc / Canary** categories. 107 108 1. **Main** 109 * **Enable DOM Invader** – global switch. 110 * **Postmessage interception** – turn on/off message logging; sub-toggles for auto-mutation. 111 * **Custom Sources/Sinks** – *cog icon* ➜ enable/disable specific sinks (e.g. `eval`, `setAttribute`) that may break the app. 112 113 2. **Attack Types** 114 * **Prototype pollution** (with per-technique settings). 115 * **DOM clobbering**. 116 117 3. **Misc** 118 * **Redirect prevention** – block client-side redirects so the sink list isn’t lost. 119 * **Breakpoint before redirect** – pause JS just before redirect for call-stack inspection. 120 * **Inject canary into all sources** – auto-inject canary everywhere; configurable source/parameter allow-list.<sup>[[8]](#references)</sup> 121 122 4. **Canary** 123 * View / randomize / set custom canary; copy to clipboard. Changes require browser reload.<sup>[[7]](#references)</sup> 124 125 --- 126 127 ### 7. Tips & Good Practices 128 129 * **Use distinct canary** – avoid common strings like `test`, otherwise false-positives occur. 130 * **Disable heavy sinks** (`eval`, `innerHTML`) temporarily if they break page functionality during navigation. 131 * **Combine with Burp Repeater & Proxy** – replicate the browser request/response that produced a vulnerable state and craft final exploit URLs. 132 * **Remember frame scope** – sources/sinks are displayed per browsing context; vulnerabilities inside iframes might need manual focus. 133 * **Export evidence** – right-click the DOM Invader panel ➜ *Save screenshot* to include in reports. 134 135 --- 136 137 ## References 138 139 - [1] [PortSwigger: DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader) 140 - [2] [PortSwigger: Enabling DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/enabling) 141 - [3] [PortSwigger: Testing for DOM XSS using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/dom-xss) 142 - [4] [PortSwigger: Testing for web message vulnerabilities using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/web-messages) 143 - [5] [PortSwigger: Testing for prototype pollution using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/prototype-pollution) 144 - [6] [PortSwigger: Testing for DOM clobbering using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/dom-clobbering) 145 - [7] [PortSwigger: DOM Invader canary settings](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/canary) 146 - [8] [PortSwigger: DOM Invader miscellaneous settings](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/misc)