SecuriTEA & Crumpets - Episode 7 - Dr.-Ing. Mario Heiderich - DOMPurify

Опубликовано: 02 Август 2026
на канале: Lewis Ardern
490
16

SecuriTEA & Crumpets is a series where security professionals come together to talk about their background, research, and interesting topics. The seventh episode is with Dr. Mario Heiderich. He is a power house in the world of application security, he even has a Ph.D. in XSS. Mario is the founder of a "boutique" pen testing firm cure53.de. He is the creator of DOM Purify one of the most used client-side sanitizers in the world.

00:00 Intro
01:20 Ph.D. in XSS
02:44 Being a lecturer
05:30 Overseeing student projects
07:44 Research Group
10:31 Cure53
10:55 What made you start Cure53?
14:14 No-longer active on twitter
19:17 And there is fire where we walk
20:18 Public pentests
21:10 Smart Sheriff Issues
25:40 How do you publicly release your pentests?
29:53 Three important things on how to start a pentest company
33:19 Internet Explorer Quirks / Microsoft
35:35 Compatibility mode
40:38 What is the research work you have done, you are proud of?
42:42 Building html5sec.org out of anger
46:00 Browser Security Whitepaper
48:30 DOMPurify
53:27 What is MXSS?
1:01:11 What are the technical challenges maintaining a library like DOMPurify?
1:02:31 JSDOM - RESEARCH THIS
1:03:54 Web browser in-built sanitizer

References:
https://portswigger.net/research/xss-...
https://cure53.de/#publications
https://cure53.de/pentest-report_smar...
https://cure53.de/pentest-report_smar...
   • How to build your own Infosec Company  | M...  
https://html5sec.org/
https://github.com/cure53/browser-sec...
https://wicg.github.io/sanitizer-api/
https://www.usenix.org/conference/eni...
https://github.com/cure53/DOMPurify
https://research.securitum.com/dompur...
https://wicg.github.io/sanitizer-api/