The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

ESSENTIAL SKILLS

sefa | Last updated: Jun 22, 2024 12:33PM UTC

Hi, I couldn't fully understand the phrase "As this will remain encoded server-side, it may go undetected until the browser decodes it again," written under the "Obfuscation via unicode escaping" section on the page essential-skills/obfuscating-attacks-using-encodings. Since DOM XSS is a client-side vulnerability and, as far as I know, is triggered at runtime in the browser, there might be a mistake here. If I am mistaken, could you please help me correct my understanding?

Michelle, PortSwigger Agent | Last updated: Jun 24, 2024 01:44PM UTC