Clobbering the clobbered — Advanced DOM Clobbering

Based on @SecurityMB XSS Challenge

9 min readSep 26, 2019


This is a write-up for an XSS Challenge that popped out on Twitter recently. In this article, I will talk through three different approaches that one could take to solve the challenge, including the shortest among the submitted solutions. The latter resulted in a surprising discovery of how HTML is parsed.




Security enthusiast that loves playing CTFs and hunting for bugs in the wild. Also likes to do some chess once in a while.