sirdarckcat
Saturday, February 11, 2017
Vulnerability disclosure in an era of vulnerability rewards
›
Note : This (and every post in this blog) is a personal blog post which expresses my personal opinion, and doesn't necessarily have to b...
Wednesday, February 08, 2017
🤷 Unpatched (0day) jQuery Mobile XSS
›
TL;DR - Any website that uses jQuery Mobile and has an open redirect is now vulnerable to XSS - and there's nothing you can do about it...
Wednesday, January 25, 2017
Fighting XSS with 🛡 Isolated Scripts
›
TL;DR : Here's a proposal for a new way to fight Cross-Site Scripting vulnerabilities called Isolated Scripts . You have an open-source...
Monday, January 23, 2017
Measuring web security mitigations
›
Summary : This past weekend I spent some time implementing a prototype for a web security mitigation, and I also spent some time thinking w...
Tuesday, December 27, 2016
How to bypass CSP nonces with DOM XSS 🎅
›
TL;DR - CSP nonces aren't as effective as they seem to be against DOM XSS. You can bypass them in several ways. We don't know how ...
Saturday, December 10, 2016
Vulnerability Pricing
›
What is the right price for a security vulnerability? TL;DR: Vendors should focus on vulnerabilities, not on exploits. Vulnerabilities sho...
Monday, March 28, 2016
Creating a Decentralized Security Rewards Market
›
Imagine a world where you, a security researcher, could make money on your open source contributions, and your expertise about the security ...
‹
›
Home
View web version