DEF CON 33 - AutoDetection & Exploitation of DOM Clobbering Vuln at Scale - Zhengyu Liu, Jianjia Yu

DEF CON 33 - AutoDetection & Exploitation of DOM Clobbering Vuln at Scale - Zhengyu Liu, Jianjia Yu

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 37:44

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video presents Hawk, an automated framework for detecting and exploiting DOM clobbering vulnerabilities at scale. The main goal is to identify and exploit DOM clobbering gadgets—where attacker-controlled DOM elements hijack JavaScript lookups—by combining HTML injection with precise payload generation. This enables cross-site scripting (XSS) and other attacks in real-world web applications.

Key Takeaways:
• DOM clobbering occurs when attacker-controlled HTML elements with ID/name attributes hijack JavaScript lookups (e.g., document.script), enabling arbitrary code execution 2:15.
• Existing tools fail due to dynamic JavaScript behavior and lack of control-flow constraints; Hawk overcomes this with dynamic taint tracking and symbolic DOM constraint solving 5:02.
• Hawk analyzes 5,000 websites and finds 497 exploitable DOM clobbering gadgets in popular libraries (e.g., Webpack, Astro, MathJax) and frameworks 21:15.
• Real-world end-to-end exploits are demonstrated, including 11 XSS and 1 CSRF attacks via HTML injection combined with DOM clobbering in Jupyter Lab and Canvas LMS 31:25.

Hawk’s open-source tool, dataset, and research reveal the widespread risk of DOM clobbering and provide practical pathways for zero-day discovery and exploitation.

Sources:

  • 2:15 Explanation of DOM clobbering and attack chain.
  • 5:02 Challenges in existing tools and Hawk’s solution.
  • 21:15 Large-scale study results and gadget discovery.
  • 31:25 End-to-end exploit examples in Jupyter Lab and Canvas LMS.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

We'll go ahead and get started. We'll have Jang Yu Leu and Jinga Yu present on the domino effect. Let's clap it out for them. >> Hello everyone. should get started. >> Okay. So, hello everyone. Uh, welcome to our talk the domino effect automated detection and exploitation of dump clobility at scale. So I'm Jung Yo and this my collaborator uh Jenu and this a joint work with Tai Kong and my Wester in are both PhD student from Jak University uh focus on web security and software security and we spent our most of time studying vulnerabilities uh building security testing tools and thinking about how to make the modern world a better place and today we're excited to share our research on doming So I will first start a very quick overview of what dump clobbering is and then explain the challenge…