www.therceman.dev
Almost 800 followers, wow 😀
Almost 800 followers, wow 😀
SSRF: PDF iframe Injection
Cheers!
SSRF: PDF iframe Injection
Cheers!
SSRF: PDF iframe Injection
Cheers!
SSRF: PDF iframe Injection
Cheers!
Parameter Manipulation:
Email Link Hijacking
Cheers!
Parameter Manipulation:
Email Link Hijacking
Cheers!
Parameter Manipulation:
Email Link Hijacking
Cheers!
Parameter Manipulation:
Email Link Hijacking
Cheers!
XSS Filter Bypass: mXSS
Cheers!
XSS Filter Bypass: mXSS
Cheers!
XSS Filter Bypass: mXSS
Cheers!
XSS Filter Bypass: mXSS
Cheers!
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
book.therceman.dev
Cheers!
book.therceman.dev
Cheers!
book.therceman.dev
Cheers!
book.therceman.dev
Cheers!
XSS WAF Bypass by multi-char HTML entities
fj translates to fj
>⃒ translates to > + [?]
<⃒ translates to < + [?]
[?] - Unicode symbol
XSS WAF Bypass by multi-char HTML entities
fj translates to fj
>⃒ translates to > + [?]
<⃒ translates to < + [?]
[?] - Unicode symbol
go.bsky.app/GD7hKPX
go.bsky.app/GD7hKPX
Cheers!
Cheers!
youtu.be/JERBqoTllaE?...
youtu.be/JERBqoTllaE?...
You can hide your XSS payload inside SVG or Math element to bypass the XSS Sanitizer or WAF filter
Cheers!
You can hide your XSS payload inside SVG or Math element to bypass the XSS Sanitizer or WAF filter
Cheers!
Edition: Pre-Sale
Tricks: 18 Tips and Tricks
Price: $13.37 (33% OFF)
🔗 book.therceman.dev
Edition: Pre-Sale
Tricks: 18 Tips and Tricks
Price: $13.37 (33% OFF)
🔗 book.therceman.dev