In this lab walkthrough, we uploaded an SVG file with a nefarious XML payload inside to extract data.
Follow along here 👇
portswigger.net/web-security/x…
We love a bit of competition here at the Web Security Academy, and that's why we have the Hall of Fame!
We announce each of our labs on X, so don't miss out.
Absolutely incredible research by @garethheyes
One email, two readers.
:before and :after inject text into the page. An AI browser reading the message does not see that text.
opacity:0.00000001 does the reverse. The victim cannot read the element, but the AI browser can.
Just because there's no XML in the body, doesn't mean it won't be parsed as XML! It's rare, but it happens.
Learn more here 👇
portswigger.net/web-security/x…
Nothing makes us prouder than educating the world's next generation of hackers!
Over the years we've:
👨💻 Released 247 free labs
👨💻 Served 90,000 up and coming hackers
👨💻 Ran an 18,000 strong Discord community
👨💻 Served hackers in 170 countries
Hackers are more important than