Desync vulnerabilities stemming from HP2 downgrading continue to plague even the largest vendors, have a read to find out how!
github.com/rs/cors/issu...
github.com/rs/cors/issu...
It now detects response timing differences.
thespanner.co.uk/shadow-repea...
It now detects response timing differences.
thespanner.co.uk/shadow-repea...
github.com/CoreyD97/Ins...
github.com/CoreyD97/Ins...
https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
Read JavaScript for Hackers to master creative XSS techniques and understand exactly why they work.
🧠 Learn to think like a hacker
⚡ Master the art of payload design
Grab your copy 👉 www.amazon.com/JavaScript-h...
Read JavaScript for Hackers to master creative XSS techniques and understand exactly why they work.
🧠 Learn to think like a hacker
⚡ Master the art of payload design
Grab your copy 👉 www.amazon.com/JavaScript-h...
portswigger.net/research/tal...
portswigger.net/research/tal...
Watch the livestream here: m.youtube.com/watch?v=T009...
Watch the livestream here: m.youtube.com/watch?v=T009...
@tib3rius.bsky.social & @swiftsecur.bsky.social chat with Julien Richard about his war stories!
Thank you to @portswigger.net for sponsoring today's episode! Check out portswigger.net/burp/ai to learn more about AI in Burp Suite.
Links below!
@tib3rius.bsky.social & @swiftsecur.bsky.social chat with Julien Richard about his war stories!
Thank you to @portswigger.net for sponsoring today's episode! Check out portswigger.net/burp/ai to learn more about AI in Burp Suite.
Links below!
"The technique is what matters", it's still an awesome slide 🔥
"The technique is what matters", it's still an awesome slide 🔥