@jub0bs just wrote an awesome post about an intricate bug chain! ? It covers postMessage, JSONP, WAF bypass, DOM-based XSS, CORS & CSRF. Must-read for all #BugBounty hunters! ? Check it out here: https://t.co/zRpWc0bA8O ?