sirdarckcat

Saturday, February 11, 2017

Vulnerability disclosure in an era of vulnerability rewards

›
Note : This (and every post in this blog) is a personal blog post which expresses my personal opinion, and doesn't necessarily have to b...
Wednesday, February 08, 2017

🤷 Unpatched (0day) jQuery Mobile XSS

›
TL;DR - Any website that uses jQuery Mobile and has an open redirect is now vulnerable to XSS - and there's nothing you can do about it...
Wednesday, January 25, 2017

Fighting XSS with 🛡 Isolated Scripts

›
TL;DR : Here's a proposal for a new way to fight Cross-Site Scripting vulnerabilities called  Isolated Scripts . You have an open-source...
Monday, January 23, 2017

Measuring web security mitigations

›
Summary : This past weekend I spent some time implementing a prototype for a web security mitigation, and I also spent some time thinking w...
Tuesday, December 27, 2016

How to bypass CSP nonces with DOM XSS 🎅

›
TL;DR  - CSP nonces aren't as effective as they seem to be against DOM XSS. You can bypass them in several ways. We don't know how ...
Saturday, December 10, 2016

Vulnerability Pricing

›
What is the right price for a security vulnerability? TL;DR: Vendors should focus on vulnerabilities, not on exploits. Vulnerabilities sho...
Monday, March 28, 2016

Creating a Decentralized Security Rewards Market

›
Imagine a world where you, a security researcher, could make money on your open source contributions, and your expertise about the security ...
‹
›
Home
View web version
Powered by Blogger.