Blaklis
blaklis.bsky.social
Blaklis
@blaklis.bsky.social
CTF player with The Flat Network Society - bug bounty & web security research
@mizu.re just launched a service to list XSS gadgets that bypass CSP or sanitizers. A good thing to keep in the arsenal - and a good thing to contribute on, if you have something to add!

gmsgadget.com
GMSGadget
gmsgadget.com
July 24, 2025 at 11:00 PM
Very cool project!
Now live on tools.honoki.net/smuggler.html

Let me know what you think! ✨
July 23, 2025 at 4:32 PM
DUCTF released a challenge that was really fun, from hash_kitten - @assetnote.io !

Happy to be part of the only team that solved it. It was a challenge full of nice tricks - check it out!

github.com/DownUnderCTF...

Read @assetnote.io partial writeup on it : slcyber.io/assetnote-se...
Challenges_2025_Public/web/legendary at main · DownUnderCTF/Challenges_2025_Public
Files + Solutions for DownUnderCTF 2025 Challenges - DownUnderCTF/Challenges_2025_Public
github.com
July 21, 2025 at 9:37 AM
Sansec published a small article regarding a serious cache poisonning issue I recently found in Adobe Commerce : sansec.io/research/mag...

It is quite a good idea to patch your instances if it's not done - there's even an isolated patch for it!

helpx.adobe.com/security/pro...
Adobe patches critical Magento admin takeover via menu injection
A new attack on Adobe Commerce may break the menu bar for admin users. If your menu bar is missing, someone is stealing your session via CVE-2025-47110.
sansec.io
June 26, 2025 at 3:03 PM