daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

dom-invader.md (7935B)


      1 ---
      2 title: "DOM Invader"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/dom-invader.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/dom-invader.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # DOM Invader
     14 
     15 ## DOM Invader
     16 
     17 DOM Invader is a browser tool installed in **Burp Suite's built-in Chromium browser**. It assists in **detecting DOM XSS and other client-side vulnerabilities** (prototype pollution, DOM clobbering, etc.) by automatically **instrumenting JavaScript sources and sinks**. The extension ships with Burp and only needs to be enabled.<sup>[[1]](#references)</sup>
     18 
     19 DOM Invader adds a tab to the browser’s DevTools panel that lets you:
     20 
     21 1. **Identify controllable sinks** in real time, including context (attribute, HTML, URL, JS) and applied sanitization.
     22 2. **Log, edit and resend `postMessage()` web-messages**, or let the extension mutate them automatically.
     23 3. **Detect client-side prototype-pollution sources and scan for gadget→sink chains**, generating PoCs on-the-fly.
     24 4. **Find DOM clobbering vectors** (e.g. `id` / `name` collisions that overwrite global variables).
     25 5. **Fine-tune behaviour** via a rich Settings UI (custom canary, auto-injection, redirect blocking, source/sink lists, etc.).
     26 
     27 ---
     28 
     29 ### 1. Enable it
     30 
     31 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281129%29.png" alt=""><figcaption></figcaption></figure>
     32 
     33 1. Open **Proxy ➜ Intercept ➜ Open Browser** (Burp’s embedded browser).
     34 2. Click the **Burp Suite** logo (top-right). If it’s hidden, click the jigsaw-piece first.
     35 3. In **DOM Invader** tab, toggle **Enable DOM Invader** ON and press **Reload**.
     36 4. Open DevTools ( `F12` / Right-click ➜ Inspect ) and dock it. A new **DOM Invader** panel appears.
     37 
     38 > Burp remembers the state per profile. Disable it under *Settings ➜ Tools ➜ Burp’s browser ➜ Store settings...* if required.<sup>[[2]](#references)</sup>
     39 
     40 ### 2. Inject a Canary
     41 
     42 A **canary** is a random marker string (e.g. `xh9XKYlV`) that DOM Invader tracks. You can:<sup>[[3]](#references)</sup>
     43 
     44 * **Copy** it and manually inject it in parameters, forms, Web-Socket frames, web-messages, etc.
     45 * Use **Inject URL params / Inject forms** buttons to open a new tab where the canary is appended to every query key/value or form field automatically.
     46 * Search for an **empty canary** to reveal all sinks regardless of exploitability (great for reconnaissance).
     47 
     48 #### Custom canary (2025+)
     49 
     50 Burp 2024.12 introduced **Canary settings** (Burp-logo ➜ DOM Invader ➜ Canary). You can:<sup>[[7]](#references)</sup>
     51 
     52 * **Randomize** or set a **custom string** (helpful for multi-tab testing or when the default value appears naturally on the page).
     53 * **Copy** the value to clipboard.
     54 * Changes require **Reload**. 
     55 
     56 ---
     57 
     58 ### 3. Web-messages (`postMessage`)
     59 
     60 The **Messages** sub-tab records every `window.postMessage()` call, showing `origin`, `source`, and `data` usage.<sup>[[4]](#references)</sup>
     61 
     62 • **Modify & resend**: double-click a message, edit `data`, and press **Send** (Burp Repeater-like).
     63 
     64 • **Auto-fuzz**: enable **Postmessage interception ➜ Auto-mutate** in settings to let DOM Invader generate canary-based payloads and replay them to the handler.
     65 
     66 Field meaning recap:
     67 
     68 * **origin** – whether the handler validates `event.origin`.
     69 * **data** – payload location. If unused, the sink is irrelevant.
     70 * **source** – iframe / window reference validation; often weaker than strict‐origin checking.
     71 
     72 ---
     73 
     74 ### 4. Prototype Pollution
     75 
     76 Enable under **Settings ➜ Attack types ➜ Prototype pollution**.<sup>[[5]](#references)</sup>
     77 
     78 Workflow:
     79 
     80 1. **Browse** – DOM Invader flags pollution **sources** (`__proto__`, `constructor`, `prototype`) found in URL/query/hash or JSON web-messages.
     81 2. **Test** – clicks *Test* to open a PoC tab where `Object.prototype.testproperty` should exist:
     82 
     83    ```javascript
     84    let obj = {};
     85    console.log(obj.testproperty); // ➜ 'DOM_INVADER_PP_POC'
     86    ```
     87 3. **Scan for gadgets** – DOM Invader bruteforces property names and tracks whether any end up in dangerous sinks (e.g. `innerHTML`).
     88 4. **Exploit** – when a gadget-sink chain is found an *Exploit* button appears that chains source + gadget + sink to trigger alert.
     89 
     90 Advanced settings (cog icon):
     91 
     92 * **Remove CSP / X-Frame-Options** to keep iframes workable during gadget scanning.
     93 * **Scan techniques in separate frames** to avoid `__proto__` vs `constructor` interference.
     94 * **Disable techniques** individually for fragile apps. 
     95 
     96 ---
     97 
     98 ### 5. DOM Clobbering
     99 
    100 Toggle **Attack types ➜ DOM clobbering**. DOM Invader monitors dynamically created elements whose `id`/`name` attributes collide with global variables or form objects (`<input name="location">` → clobbers `window.location`). An entry is produced whenever user-controlled markup leads to variable replacement.<sup>[[6]](#references)</sup>
    101 
    102 ---
    103 
    104 ## 6. Settings Overview (2025)
    105 
    106 DOM Invader is now split into **Main / Attack Types / Misc / Canary** categories.
    107 
    108 1. **Main**
    109    * **Enable DOM Invader** – global switch.
    110    * **Postmessage interception** – turn on/off message logging; sub-toggles for auto-mutation.
    111    * **Custom Sources/Sinks** – *cog icon* ➜ enable/disable specific sinks (e.g. `eval`, `setAttribute`) that may break the app. 
    112 
    113 2. **Attack Types**
    114    * **Prototype pollution** (with per-technique settings).
    115    * **DOM clobbering**.
    116 
    117 3. **Misc**
    118    * **Redirect prevention** – block client-side redirects so the sink list isn’t lost.
    119    * **Breakpoint before redirect** – pause JS just before redirect for call-stack inspection.
    120    * **Inject canary into all sources** – auto-inject canary everywhere; configurable source/parameter allow-list.<sup>[[8]](#references)</sup>
    121 
    122 4. **Canary**
    123    * View / randomize / set custom canary; copy to clipboard. Changes require browser reload.<sup>[[7]](#references)</sup>
    124 
    125 ---
    126 
    127 ### 7. Tips & Good Practices
    128 
    129 * **Use distinct canary** – avoid common strings like `test`, otherwise false-positives occur.
    130 * **Disable heavy sinks** (`eval`, `innerHTML`) temporarily if they break page functionality during navigation.
    131 * **Combine with Burp Repeater & Proxy** – replicate the browser request/response that produced a vulnerable state and craft final exploit URLs.
    132 * **Remember frame scope** – sources/sinks are displayed per browsing context; vulnerabilities inside iframes might need manual focus.
    133 * **Export evidence** – right-click the DOM Invader panel ➜ *Save screenshot* to include in reports.
    134 
    135 ---
    136 
    137 ## References
    138 
    139 - [1] [PortSwigger: DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader)
    140 - [2] [PortSwigger: Enabling DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/enabling)
    141 - [3] [PortSwigger: Testing for DOM XSS using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/dom-xss)
    142 - [4] [PortSwigger: Testing for web message vulnerabilities using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/web-messages)
    143 - [5] [PortSwigger: Testing for prototype pollution using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/prototype-pollution)
    144 - [6] [PortSwigger: Testing for DOM clobbering using DOM Invader](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/dom-clobbering)
    145 - [7] [PortSwigger: DOM Invader canary settings](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/canary)
    146 - [8] [PortSwigger: DOM Invader miscellaneous settings](https://portswigger.net/burp/documentation/desktop/tools/dom-invader/settings/misc)