renniepak

@renniepak.nl

Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)

I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)

Finding XSS on Shazzer (literally) | Jorian Woltjer

How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...

jorianwoltjer.com

Gareth Heyes@garethheyes.co.uk · 2mo ago

Just want to say @jorianwoltjer.com is awesome. You'll find out why soon...

Looking back on #hh0526 with a big smile. 😊 We brought together 22 hackers from 9 different nationalities in the wonderful city of Utrecht for a day of pure bug bounty fun, hacking on @intigriti.com programs with special event bonuses included.

eval(unescape(escape`!򩡵򫡣򭁩򫱮ꈊ򚀩򮱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯀡򩰮򬁬򨑹򪑮򩰩򬡥򭁵򬡮򘁤򫱣򭑭򩑮򭀮򩁩򬱰򨑴򨱨򡑶򩑮򭀨򫡥򭰠򢱥򮑢򫱡򬡤򡑶򩑮򭀨򘡫򩑹򩁯򭱮򘠬򮱫򩑹򠱯򩁥ꎣ򜡽򚐩򛁶򫱩򩀠򬱥򭁔򪑭򩑯򭑴ꊊⱐ򜀩򞱬򩑴򘁴ꏑ򛁮򛁯ꏐ򛁩ꏐ򛁐򟐢򬁴򩑲򫱤򨑣򭁹򫀢򛁳򟐨򚐽򟡻򪑦򚀡򭀩򬡥򭁵򬡮򞱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯁧򛡣򬡡򬱨򩑤򚑲򩑴򭑲򫠠򭀽򜀻򫁥򭀠򩠽򩰮򭁒򩑸򛁣򟑧򛡨򫱲򪑺򫱮򛡯򨡳򭁡򨱬򩑳򛁲򟑧򛡣򭑲򬡥򫡴򤱰򩑥򩀬򭐽ⴐ򛑲ꋱ򜀬򭰽򩠮򮁐򫱳򛁗򟑦򛡣򫱮򩡩򩰮򭱩򩁴򪀬򮀽򭰫򥰻򪑦򚁯򚑻򪐫򚰻򫁥򭀠򩐽򜐻򩡯򬠨򫁥򭀠򪠠򫱦򘁣򚑻򫁥򭀠򥀽򪠮򭁹򬁥򠱯򫡦򪑧򞱩򩠨򥀮򭁹򬁥򟐽򤀦򙡪򛡹򤁯򬰼ꏗ򝐩򨱯򫡴򪑮򭑥򞱩򩠨򪠮򮁐򫱳򟁸ꊳ򜀦򙡪򛡸򤁯򬰫򥀮򭱩򩁴򪀪򪠮򬱩򮡥򟡷ꋑ򜀦򙡦򛡹򤁯򬰫򩠮򨱯򫡦򪑧򛡨򩑩򩱨򭀾򪠮򮑐򫱳򚑻򩐽򜀻򨡲򩑡򪱽򯑥򙠦򩠮򪡵򫑰򪑮򩰦򙡩ꏥ򙠦򩠮򩑮򩁊򭑭

When reviewing pull requests with new additions for CSPBypass.com, I often find myself questioning how useful a given entry actually is. If no websites whitelist a specific host, there is little point in adding it.

What windows or MacOs files reliably contain the username of the currently logged in user WITHOUT that username being part of the file path?

Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically don’t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.

Bild

Made hacking rooms work in real time. This demo connects three browsers with real time editing on. From Chrome I edit some HTML. This gets sent over websockets to the other browsers which call postMessage to a blob with a sandboxed iframe.

Such a DOM XSS tease: var s=document.createElement('style');s.innerHTML=decodeURIComponent(location.hash.slice(1));document.head.appendChild(s)