Imagine you have a XSS vulnerability but you have a undefined variable before your injection. Is all hope lost? Not at all you can use a technique called XSS Hoisting to declare the variable and continue your exploit. Thanks to ycam_asafety for the submission. portswigger.net/web-security...
Johan Carlsson
@joaxcar.bsky.social
Full time bug bounty hunter. Look for ”joaxcar” on other platforms
Made a new small challenge where you have to break out of a web worker to leak a token in the URL Only works in Firefox and Safari joaxcar.com/fun/worker/a...
Web Worker Test
joaxcar.com
Feels like a good time to double down on this
I am a huge fan of the #BuyFromEU movement! So far, I've ditched a lot of US stuff already, including Microsoft, Dropbox, 1Password, Notion, Grammarly, Amazon, Slack, and Google. This helped a lot: european-alternatives.eu
I often know that I know something. But when having to ask quickly, I stumble. I might have to start generating some "flash card" style questions for myself to try to ingrain some knowledge a bit deeper. This is an example from earlier this week. It's not hard, but how quick and certain are you?
I am a huge fan of the #BuyFromEU movement! So far, I've ditched a lot of US stuff already, including Microsoft, Dropbox, 1Password, Notion, Grammarly, Amazon, Slack, and Google. This helped a lot: european-alternatives.eu
Homepage | European Alternatives
We help you find European alternatives for digital service and products, like cloud services and SaaS products.
european-alternatives.eu
Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...
Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter
After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.
gelu.chat
Double-Clickjacking, or "press buttons on other sites without preconditions". After seeing and experimenting with this technique for a while, I cooked up a variation that combines many small tricks and ends up being quite convincing. Here's a flexible PoC: jorianwoltjer.com/blog/p/hacki...
The Ultimate Double-Clickjacking PoC | Jorian Woltjer
Combing a lot of browser tricks to create a realistic Proof of Concept for the Double-Clickjacking attack. Moving a real popunder with your mouse cursor and triggering it right as you're trying to bea...
jorianwoltjer.com
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall joaxcar.com/blog/2025/05...
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
joaxcar.com
I must have screwed up when setting up bluesky. Added to many “starterpacks”. My feed has been underwhelming. Any one have any idea if there is an active bug bounty community here and how to tap into it?
The legendary @joaxcar.bsky.social made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below: jorianwoltjer.com/blog/p/hacki...
Intigriti May XSS Challenge (0525) | Jorian Woltjer
A challenge by @joaxcar with a small but complex XSS chain, hitting DOM Clobbering with a race condition and abusing a cool URL parsing quirk in JavaScript.
jorianwoltjer.com
I made a small Cross Site Scripting challenge for Intigriti that is live now. Feel free to practice your web hacking skills on it. “Based on a true story” as they say challenge-0525.intigriti.io
May Challenge - Intigriti
Find the XSS and WIN Intigriti swag.
challenge-0525.intigriti.io
Getting feedback like this is what motivates me to work, again and again, on my Burp Suite training course. Thanks @joaxcar.bsky.social ☺️
Following other's lead, I put together an XSS challenge to solve a somewhat tricky injection I'd come across. In producing the challenge I came up with my solution (so in that way I guess it served it's purpose) but interested in how other's would approach it 🤔 blog.ajxchapman.com/xss/challeng...
Finally taking the last steps to "remove" my Twitter account. As I don't want to get impersonated, I will just empty it out and leave it to die slowly. Is there any other way? Must admit my timeline here is not as interesting, but I guess that's up to me to fix.
Little known trick to bypass CSP feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
Three years ago, @joaxcar.bsky.social was just starting out with bug bounty. Today, he’s GitLab’s TOP1, has bugs on Google and Apple programs, and a reputation as one of the best client-side hackers. Check out our interview🔥
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
One of my favorite bugs from last year
SSRFs can be tough to make critical without cloud metadata, especially against a target like GitLab that strengthens its infra with every SSRF. Yet @joaxcar.bsky.social broke through with the first critical SSRF on GitLab since 2020. Enjoy our explanation from Sweden! 🇸🇪
Another banger pod from BBRE! Really needed this inspiration going into the new year. Never thought about logger++ and elastic, need to test that out
Attending a live hacking event is already an accomplishment. My guest, doomerhunter, not only attended but ranked in the top 10 every time and won awards like most impactful team or got the S&Ts recognitions. In this interview, we'll uncover his secrets🔥
Here is (finally) the writeup and conclusion of the challenge: joaxcar.com/blog/2024/12... Maybe not the best write-up, but I have to allow myself to actually post, rather than refactor, posts. I hope someone finds it useful. And thanks everyone that participated. Special shoutout to @terjanq.me
Sideloading external scripts: a code golf challenge - Johan Carlsson
joaxcar.com
A small code-golf web challenge (free research from you, for me), how short can you make a "fetch content and execute it inline". There is a CSP in a meta tag. Goal: get the content from the file hack.js and have it inserted in the page. like in the image joaxcar.com/xss/self.html
⚠️Challenge time again⚠️ It is based on a real-world situation. Use the HTML injection to leak the flag to an external domain ☃️ This time, send solutions in DM; we don't want to spoil the fun. I also might want to patch any obvious blunder I made creating it joaxcar.com/xss/outer.ht...
Was a blast hanging out with @gregxsunday.bsky.social a few hours in gray and cold Gothenburg! Glad that we finally got to meet in real life
Just recorded the interview and a bug writeup with the incredible and full of ideas @joaxcar.bsky.social in Sweden😎 Can't wait for them to get published🔥
A small code-golf web challenge (free research from you, for me), how short can you make a "fetch content and execute it inline". There is a CSP in a meta tag. Goal: get the content from the file hack.js and have it inserted in the page. like in the image joaxcar.com/xss/self.html
Dear Bug Bounty programs, You cannot simultaneously prohibit bug escalation and pivoting _and_ insist reports include accurate evidenced risk calculations. Regards, A tired bug hunter
Doing some @portswigger.net advent calendar this year as well. Join me on advent.j15.se Its not affiliated with Portswigger but it will link you to one of their chapters each day (random for max excitement) Its created 100% using Cursor so any bugs is AI’s fault
PortSwigger Advent Calendar
advent.j15.se
An interesting take on the behavior of SAAS companies to put security features in paid plans by @c_r_holm. With an accompanying "name and shame" list raz.sh/blog/2024-11...
Weaponizing SSO for profit - Raz Blog
raz.sh
A full patch release without my name in it. Am I loosing my game?! Or is it the newborn messing things up.. need to fix this asap about.gitlab.com/releases/202...
GitLab Patch Release: 17.6.1, 17.5.3, 17.4.5
Learn more about GitLab Patch Release: 17.6.1, 17.5.3, 17.4.5 for GitLab Community Edition (CE) and Enterprise Edition (EE).
about.gitlab.com
Such a great deepdive into cookies. Read!
Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...
Finally, I took the 5 minutes needed (AI) to "create" the site I always wanted. I won't need to visit random ad-ridden sites just to remember the encoding of characters.. (And I know there are powerful tools and sites to do this. But I want feather light, fast, no bullshit)
Trying to sum up my "methodology". Two months ago it led to me reporting three criticals, since then it has only led to "repeat"
I hunt pretty unstructured. It often starts with finding some new thing to try; I try it, and it fails. While trying it out, I stumble upon something completely unrelated that points in a direction where I have not been before. I start digging that way. And either its gold or it just repeats again 😀
Here is the "writeup". Hope its clear enough, otherwise ask in comments. Note that there are two paths that will result in XSS. And that the "error path" can be reached in numerous different ways, like alternative 1 and 4. Alternative 5 hits the "successful path" and can also be used in many ways
Specification challenge! ☃️ Which (if any) of the href values (1-5) would pop an alert in this scenario? 🛑 No testing, just thinking! ⚠️ Warning: answers in comments (bonus: why/why not)