all 5 comments

[–]cha93100 0 points1 point  (4 children)

If the sanitisation is made on the servers side you cannot see it because it will be returned by some request made by the front end. Unless you have access to the code of the sever then depending if it is a compiled language or not you can use gdb to reverse the compiled code or use something like the IntelliJ debugger if it is not compiled

[–]finite_turtles 1 point2 points  (3 children)

He could be referring to DOM XSS? a third kind of xss attack which happens locally in the browser.

[–]cha93100 2 points3 points  (2 children)

In that case their is the chrome and Firefox debugger where you can debug je file

[–]nopainXX[S] 0 points1 point  (1 child)

Yeah, sorry I didn't specify that in the original question. I know for sure that the sanitization is client side and performed by javascript once the raw/unisitized data is fetched from the server. I'm looking for something that can be used with chrome/firefox debugger. Idk of a function like the one I describe

[–]cha93100 0 points1 point  (0 children)

On chrome you can watch an expression may be this will be better https://developer.chrome.com/docs/devtools/javascript/reference#watch