⤷ Title: Getting Keycloak working in a Strict CSP Environment
════════════════════════
𐀪 Author: Dinuka Salwathura
════════════════════════
ⴵ Time: Sun, 29 Dec 2024 13:17:57 GMT
════════════════════════
⌗ Tags: #keycloak #csp #javascript
════════════════════════
𐀪 Author: Dinuka Salwathura
════════════════════════
ⴵ Time: Sun, 29 Dec 2024 13:17:57 GMT
════════════════════════
⌗ Tags: #keycloak #csp #javascript
Medium
Getting Keycloak working in a Strict CSP Environment
Some companies have requirements like enforcing a string Content Security Policy(CSP) to increase security of its hosted web applications.
⤷ Title: What I have learnt during the implementation of the CSP header?
════════════════════════
𐀪 Author: Levent Barut
════════════════════════
ⴵ Time: Sat, 08 Feb 2025 09:25:11 GMT
════════════════════════
⌗ Tags: #application_security #http_headers #csp
════════════════════════
𐀪 Author: Levent Barut
════════════════════════
ⴵ Time: Sat, 08 Feb 2025 09:25:11 GMT
════════════════════════
⌗ Tags: #application_security #http_headers #csp
Medium
What I have learnt during the implementation of the CSP header?
There was a tough task for me and my organisation. This task is even tough for organizations that have their own application security team…
⤷ Title: Is Your Website Vulnerable? Discover the Power of Content Security Policy (CSP)!
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Mon, 17 Mar 2025 12:11:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #vulnerability #web_penetration_testing #csp
════════════════════════
𐀪 Author: Very Lazy Tech
════════════════════════
ⴵ Time: Mon, 17 Mar 2025 12:11:57 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #vulnerability #web_penetration_testing #csp
Medium
Is Your Website Vulnerable? Discover the Power of Content Security Policy (CSP)!
✨ Free Link in the first comment
⤷ Title: Vaulting over a .innerHTML sink in a Locked-Down CSP
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 19:33:48 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Sun, 27 Apr 2025 19:33:48 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
Medium
Vaulting over a .innerHTML sink in a Locked-Down CSP
This writeup explores a CSP Bypass with script-src whitelisted assets inside a .innerHTML DOM sink.
⤷ Title: Vaulting over a .innerHTML sink in a Locked-Down CSP
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 05:42:44 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
════════════════════════
𐀪 Author: SMHTahsin33
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 05:42:44 GMT
════════════════════════
⌗ Tags: #dom_xss #csp #innerhtml #xss_attack #bug_bounty
Medium
Vaulting over a .innerHTML sink in a Locked-Down CSP
This writeup explores a CSP Bypass with script-src whitelisted assets inside a .innerHTML DOM sink.
⤷ Title: Securing Your Website with Content Security Policy (CSP): Nonce vs Hash
════════════════════════
𐀪 Author: Sahaya Godson
════════════════════════
ⴵ Time: Mon, 05 May 2025 06:19:09 GMT
════════════════════════
⌗ Tags: #application_security #dast #cybersecurity #csp #xss_attack
════════════════════════
𐀪 Author: Sahaya Godson
════════════════════════
ⴵ Time: Mon, 05 May 2025 06:19:09 GMT
════════════════════════
⌗ Tags: #application_security #dast #cybersecurity #csp #xss_attack
Medium
Securing Your Website with Content Security Policy (CSP): Nonce vs Hash
In today’s fast-paced digital world, keeping your website secure isn’t just a nice-to-have — it’s a must. Cross-site scripting (XSS)…
⤷ Title: Securing the Web One Header at a Time: CSP Headers
════════════════════════
𐀪 Author: Pranieth Chandrasekara
════════════════════════
ⴵ Time: Mon, 05 May 2025 09:02:52 GMT
════════════════════════
⌗ Tags: #content_security_policy #application_security #csp #secure_programming #owasp
════════════════════════
𐀪 Author: Pranieth Chandrasekara
════════════════════════
ⴵ Time: Mon, 05 May 2025 09:02:52 GMT
════════════════════════
⌗ Tags: #content_security_policy #application_security #csp #secure_programming #owasp
Medium
Securing the Web One Header at a Time: CSP Headers
A strong content security policy is like a seatbelt for your web application — not glamorous, but critical when things go wrong.
⤷ Title: Mastering Web Security: Testing & Implementing CSP Fetch Directives Like a Pro
════════════════════════
𐀪 Author: Gaurav
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 09:27:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_attack #web_security #aem #csp
════════════════════════
𐀪 Author: Gaurav
════════════════════════
ⴵ Time: Sun, 01 Jun 2025 09:27:03 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_attack #web_security #aem #csp
Medium
Mastering Web Security: Testing & Implementing CSP Fetch Directives Like a Pro
Imagine browsing an online marketplace, clicking on a product listing, and — without realizing it — your account gets hijacked. That’s…
⤷ Title: What the Heck Is a Content Security Policy (CSP)?
════════════════════════
𐀪 Author: Sanjeevani Bhandari
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 14:42:49 GMT
════════════════════════
⌗ Tags: #front_end_development #csp #web_security #content_security_policy #cybersecurity
════════════════════════
𐀪 Author: Sanjeevani Bhandari
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 14:42:49 GMT
════════════════════════
⌗ Tags: #front_end_development #csp #web_security #content_security_policy #cybersecurity
Medium
What the Heck Is a Content Security Policy (CSP)?
You’ve seen the headers, CSP in Single-Page Applications: How to Set CSP in Real Projects
⤷ Title: Frontend Security Best Practices: Protecting Your Users and Your App
════════════════════════
𐀪 Author: Rahul Dinkar
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:05:22 GMT
════════════════════════
⌗ Tags: #frontend_development #csp #csrf_protection #web_security #xss_vulnerability
════════════════════════
𐀪 Author: Rahul Dinkar
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:05:22 GMT
════════════════════════
⌗ Tags: #frontend_development #csp #csrf_protection #web_security #xss_vulnerability
Medium
Frontend Security Best Practices: Protecting Your Users and Your App
Not a member? (Read for free here)
⤷ Title: Feroot PaymentGuard AI vs CSP: Which Script Security Tool Best Protects Payment Pages for PCI DSS 4.
════════════════════════
𐀪 Author: Feroot Security
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 16:16:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #online_shopping #ecommerce #pci #csp
════════════════════════
𐀪 Author: Feroot Security
════════════════════════
ⴵ Time: Mon, 21 Jul 2025 16:16:58 GMT
════════════════════════
⌗ Tags: #cybersecurity #online_shopping #ecommerce #pci #csp
Medium
Feroot PaymentGuard AI vs CSP: Which Script Security Tool Best Protects Payment Pages for PCI DSS 4.
TL;DR
⤷ Title: CSP Bypass in Symfony: Techniques and Prevention
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 08:01:25 GMT
════════════════════════
⌗ Tags: #vulnerability #csp_bypass #symfony #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Pentest_Testing_Corp
════════════════════════
ⴵ Time: Tue, 22 Jul 2025 08:01:25 GMT
════════════════════════
⌗ Tags: #vulnerability #csp_bypass #symfony #penetration_testing #cybersecurity
Medium
CSP Bypass in Symfony: Techniques and Prevention
Content Security Policy (CSP) is a powerful browser mechanism to mitigate cross-site scripting (XSS) and code injection. But developers…
⤷ Title: I Automated CSP Extraction and Mapped 100+ Subdomains
════════════════════════
𐀪 Author: Ibtissam hammadi
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 07:07:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #csp #reconnaissance #bug_bounty
════════════════════════
𐀪 Author: Ibtissam hammadi
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 07:07:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #infosec #csp #reconnaissance #bug_bounty
Medium
I Automated CSP Extraction and Mapped 100+ Subdomains
How I used CSP headers to automate subdomain discovery at scale — and how you can too.
⤷ Title: Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Informational #Jack Hyland #Red Team #Web App #CSP #CSP B Gone #JSONPeek
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 14:00:00 +0000
════════════════════════
⌗ Tags: #Informational #Jack Hyland #Red Team #Web App #CSP #CSP B Gone #JSONPeek
Black Hills Information Security, Inc.
Bypassing CSP with JSONP: Introducing JSONPeek and CSP B Gone - Black Hills Information Security, Inc.
A Content Security Policy (CSP) is a security mechanism implemented by web servers and enforced by browsers to prevent various types of attacks, primarily cross-site scripting (XSS). CSP works by restricting resources (scripts, stylesheets, images, etc.)…
⤷ Title: Craft Your Own CSP: A Head of Security’s Guide to Locking Down Your Website
════════════════════════
𐀪 Author: Ladecruze
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 08:20:04 GMT
════════════════════════
⌗ Tags: #security #csp #cybersecurity #bug_bounty #software_development
════════════════════════
𐀪 Author: Ladecruze
════════════════════════
ⴵ Time: Thu, 13 Nov 2025 08:20:04 GMT
════════════════════════
⌗ Tags: #security #csp #cybersecurity #bug_bounty #software_development
Medium
Craft Your Own CSP: A Head of Security’s Guide to Locking Down Your Website
Why Your Website Needs a CSP Yesterday
⤷ Title: How CSP Prevents XSS (Cross-Sight Scripting)
════════════════════════
𐀪 Author: Sabihullah Saleh
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 23:53:36 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #content_security_policy #websecurity_testing #csp #xss_attack
════════════════════════
𐀪 Author: Sabihullah Saleh
════════════════════════
ⴵ Time: Tue, 25 Nov 2025 23:53:36 GMT
════════════════════════
⌗ Tags: #xss_vulnerability #content_security_policy #websecurity_testing #csp #xss_attack
Medium
How CSP Prevents XSS (Cross-Sight Scripting)
CSP (Content Security Policy) is one of the strongest defenses against XSS attacks because it lets the browser restrict what code is…
⤷ Title: Microsoft Entra ID to Block All Third-Party Scripts on Login Page via Strict CSP
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:07:00 +0000
════════════════════════
⌗ Tags: #Microsoft #Authentication #Azure AD #Content Security Policy #CSP #Microsoft Entra ID #Secure Future Initiative #security update #XSS Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:07:00 +0000
════════════════════════
⌗ Tags: #Microsoft #Authentication #Azure AD #Content Security Policy #CSP #Microsoft Entra ID #Secure Future Initiative #security update #XSS Attack
Penetration Testing Tools
Microsoft Entra ID to Block All Third-Party Scripts on Login Page via Strict CSP
Microsoft is tightening the security of Microsoft Entra ID sign-ins, planning to block all third-party script execution on
⤷ Title: Content Security Policy (CSP) Explained: Simple Guide for XSS Defense
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 06:08:57 GMT
════════════════════════
⌗ Tags: #web #csp #bug_bounty_tips #bug_bounty_writeup #cybersecurity
════════════════════════
𐀪 Author: Muhammed Asfan | Cybersecurity Analyst
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 06:08:57 GMT
════════════════════════
⌗ Tags: #web #csp #bug_bounty_tips #bug_bounty_writeup #cybersecurity
Medium
Content Security Policy (CSP) Explained: Simple Guide for XSS Defense
If you build or hack web applications, you’ve probably seen the Content-Security-Policy header and ignored it because it looks noisy and…
⤷ Title: Lab: Reflected XSS into HTML context with nothing encoded
════════════════════════
𐀪 Author: jaejun835
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 05:31:20 GMT
════════════════════════
⌗ Tags: #csp #html #burpsuite #xs #portswigger
════════════════════════
𐀪 Author: jaejun835
════════════════════════
ⴵ Time: Thu, 26 Feb 2026 05:31:20 GMT
════════════════════════
⌗ Tags: #csp #html #burpsuite #xs #portswigger
Medium
Lab: Reflected XSS into HTML context with nothing encoded
[Problem]
⤷ Title: Content Security Policy Explained ️
════════════════════════
𐀪 Author: Marcelo Domingues
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #csp #web_development #header #xs #security
════════════════════════
𐀪 Author: Marcelo Domingues
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 15:31:01 GMT
════════════════════════
⌗ Tags: #csp #web_development #header #xs #security