Luke Jahnke

@nastystereo.com

Blogging at https://nastystereo.com

I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)

Finding XSS on Shazzer (literally) | Jorian Woltjer

How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...

jorianwoltjer.com

Gareth Heyes@garethheyes.co.uk · 2mo ago

Just want to say @jorianwoltjer.com is awesome. You'll find out why soon...

Ten years ago, I realised I needed to rewrite ActiveScan++ in Java. After putting it off for so long that artificial intelligence was literally able to do 90% of the work for me, I've done it! It's now available in the BApp store. Report issues and feature requests here -> github.com/albinowax/Ac...

GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin

ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.

github.com