Tabnabbing, target=_blank, and Related XSS Edges

Lab HTML: target=_blank without rel, opener check in the opened tab, rel=noopener fix, harmless location rewrite — no phishing kit.

September 12, 2025 · 6 min · 1169 words · Jose Adalberto Gutierrez Ochoa

DOM XSS and DOM Clobbering as Trust Problems

Lab HTML+JS page: location.hash into innerHTML, name=form clobber of a config object, harmless redacted payload, CSP as the fix.

April 14, 2021 · 6 min · 1203 words · Jose Adalberto Gutierrez Ochoa