Frans Rosén(@fransrosen) 's Twitter Profileg
Frans Rosén

@fransrosen

Co-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.

ID:80555140

calendar_today07-10-2009 11:40:00

2,7K Tweets

39,1K Followers

900 Following

Yosuke HASEGAWA(@hasegawayosuke) 's Twitter Profile Photo

見てる。セミコロン区切りで Content-Type: image/png;text/html のように複数のC-T指定をしたときの解釈の混乱を利用したXSSの手法。おもしろい。by ^\AAzara(C|N)?$, 🦭 / XSS using dirty Content Type in cloud era - Speaker Deck speakerdeck.com/flatt_security…

account_circle
Paulos Yibelo(@PaulosYibelo) 's Twitter Profile Photo

New blog alert! 🚨 Delve into an intriguing browser based web attack vector I stumbled upon that is widespread and can be used to perform ATO. I call it Cross Window Forgery. 🫧🌊🌪️🌀

paulosyibelo.com/2024/02/cross-…

account_circle
spaceraccoon | Eugene Lim(@spaceraccoonsec) 's Twitter Profile Photo

Found some interesting bugs in Excalidraw used in Meta Messenger (w Nagli and Joel Margolis (teknogeek)) as well as Microsoft Whiteboard some time ago. Here's the writeup!

spaceraccoon.dev/clipboard-micr…

account_circle
Nafeez(@skeptic_fx) 's Twitter Profile Photo

Looks like tis the xss mas season. I did discuss this in this blackhat talk almost a decade ago.
speakerdeck.com/skepticfx/domf…

This trick was a common bypass for most DOM templating engines as well.

account_circle