The browser runs untrusted code from every site at once and is supposed to keep each origin isolated from the others and from the user's data. Client-side web attacks live in the gaps of that model: getting attacker script to run in a trusted origin, making the victim's browser act against its will, and abusing the cross-origin messaging and resource-sharing mechanisms that relax isolation on purpose.
The surface#
- Cross-site scripting: running attacker script in a trusted origin (reflected, stored, and DOM-based), its execution contexts and sinks, and the filter and sanitizer bypasses that reach them.
- Request forgery and UI redress: cross-site request forgery, clickjacking, and other ways of making the victim's authenticated browser perform actions.
- The origin model: the same-origin policy and its boundaries, CORS misconfiguration,
PostMessageand cross-document messaging, WebSockets, and cross-site leaks. - Containment: bypassing or weakening the Content Security Policy and other client-side defenses, and abusing browser storage and extensions.
Seams#
Server-side injection, authentication, and logic flaws, including where a web application's server reflects or stores the data that becomes an XSS payload, are under Server > Web; this area is the browser-side execution and the origin model.