docs

Hugin DOM

Hugin — DOM testing

Test DOM-based vulnerabilities: DOM XSS, prototype pollution, postMessage sinks, DOM clobbering. Requires captured traffic or a live browser session.

Load the tools

Call tools/list with _meta.bundle = "bugclass-dom". You get: dom_invader, dom_implementation, taint.

Load the skill fragment

Read MCP resource hugin://skill/bugclass-dom for the full workflow + gotchas.

Workflow

  1. Capture traffic — drive the target through Hugin's proxy (load browser bundle).
  2. Static scan — run dom_invader scan_pp / postmessage_probe over captured flows.
  3. Identify sources — postMessage events, URL params, hash fragments that reach sinks.
  4. Dynamic augment — enable dom_invader augmentation on a live Chrome session for real-time detection.
  5. Trace — use taint to trace source→sink data flow in headless Chrome.
  6. Prove it — craft a PoC that reaches the sink with attacker-controlled data.

Rules

  • Authorised targets only. Stay in scope.
  • DOM bugs need a browser — load the browser bundle and drive Chrome through Hugin's proxy.
  • postMessage is a source, not a bug — trace it to a sink (innerHTML, eval, Function, document.write).
  • Prototype pollution: check if __proto__ or constructor.prototype is writable, then find gadgets.
  • Taint analysis is expensive — use it on specific pages, not whole crawls.
  • Evidence over assertion — show the PoC reaching the sink.