it is crazy to me that we still cannot do this
10.11.2025 15:49 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0it is crazy to me that we still cannot do this
10.11.2025 15:49 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! ๐ฅ
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs ๐
gmsgadget.com
1/4
wrote some words about vulnerabilities i found in Aviatrix during a red team cloud.google.com/blog/topics/...
23.06.2025 15:04 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. โI would say the whole process took about 15-20 minutes,โ the hacker said micahflee.com/the-signal-c...
04.05.2025 22:03 โ ๐ 271 ๐ 109 ๐ฌ 8 ๐ 14
๐ Another plugin in the Caido Store!
Introducing "Data Grep" by @bebiksior.
Extract data from requests and responses. Great for building wordlists, finding secrets, or powering your recon.
Check it out: github.com/caido-commun...
Got sniped into the challenge and ended up doing some cool XSS research :D
11 char XSS with mind-boggling race-conditions.
TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)
It's shorter than location=name !!
terjanq.me/solutions/jo...
I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec
cloud.google.com/blog/topics/...
Environments are something I've wanted for a while now.
30.11.2024 20:08 โ ๐ 12 ๐ 3 ๐ฌ 0 ๐ 0
My latest blog post is live! nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far
challenge-xss.quiz.flatt.training
add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsec
21.11.2024 17:16 โ ๐ 5 ๐ 1 ๐ฌ 0 ๐ 0yeah wrote this yrs ago, would not use this as-is ๐
15.11.2024 22:46 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0
shocking how efficient this method is. patience > crazy exploits
github.com/ldionmarcil/...