I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! ๐ฅ
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs ๐
gmsgadget.com
1/4
24.07.2025 15:31
๐ 23
๐ 13
๐ฌ 1
๐ 0
With @gelu.chat, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! ๐
If you have some time this weekend, give it a try! ๐
๐ pwnme.phreaks.fr
28.02.2025 21:23
๐ 14
๐ 4
๐ฌ 0
๐ 1
Apparently, navigating to a javascript: URL returning a string will write it as HTML to the DOM. This allows for an interesting XSS payload:
x.com/icesfont2/st...
05.12.2024 11:52
๐ 12
๐ 2
๐ฌ 0
๐ 0
Check out the blog post for a full writeup and some other cool stuff :)
bsky.app/profile/jori...
27.11.2024 16:02
๐ 1
๐ 1
๐ฌ 0
๐ 0
My challenge has been out for about a week with only one half-intended solution, so here's my solution!
27.11.2024 16:02
๐ 1
๐ 1
๐ฌ 1
๐ 0
My latest blog post is live! nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
27.11.2024 09:10
๐ 79
๐ 29
๐ฌ 3
๐ 4
Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE.
Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
22.11.2024 05:50
๐ 51
๐ 24
๐ฌ 1
๐ 0
Nice idea, I would love to be on the list!
23.11.2024 17:32
๐ 2
๐ 0
๐ฌ 0
๐ 0
EP 163 | DomPurify & Bootstrap n-days + Frontend tricks Ft. @Geluchat, @kevin_mizu
YouTube video by Laluka
P1/3 : DomPurify & Bootstrap n-days + Frontend tricks Ft. @geluchat.bsky.social @mizu.re ๐
www.youtube.com/watch?v=fnYS...
22.11.2024 16:58
๐ 2
๐ 1
๐ฌ 0
๐ 1
I've just published 'Smashing the state machine: the true potential of web race conditions'! Dive in to arm yourself with novel techniques & tooling, and help reshape this attack class:
https://portswigger.net/research/smashing-the-state-machine
09.08.2023 19:30
๐ 6
๐ 6
๐ฌ 1
๐ 0
Hello World \o/
05.08.2023 21:37
๐ 8
๐ 0
๐ฌ 0
๐ 0