Authorized security audit - testing sanitization of HTML payloads when Remarkable parser is bypassed.
Testing mutation XSS where style tags may be stripped but inner content preserved:
Testing image tag event handler injection:
Testing javascript: and data: URI schemes in anchors:
link1 link2 link3 hive-schemeTesting iframe injection vectors:
Testing interactive element event handlers:
x xTesting CSS and attribute injection in tables:
| x |
| x |
Testing picture/source element injection:
Testing SVG and MathML injection (should be stripped):
xTesting DOM clobbering vectors:
protoTesting post-sanitization embed replacement bypass:
~~~ embed:test twitter metadata:PHNjcmlwdD5hbGVydCgndHdpdHRlci14c3MnKTwvc2NyaXB0Pg== ~~~ ~~~ embed:test reddit metadata:fDxzY3JpcHQ+YWxlcnQoJ3JlZGRpdC14c3MnKTwvc2NyaXB0PnxodHRwczovL3JlZGRpdC5jb20vci90ZXN0L2NvbW1lbnRzLzEvcG9zdHx0ZXN0 ~~~This post is part of an authorized security audit. All payloads are for testing sanitization only.