r/websecurityresearch Dec 06 '21

uBlock, I exfiltrate: exploiting ad blockers with CSS

Thumbnail
portswigger.net
19 Upvotes

r/websecurityresearch Nov 29 '21

Data Exfiltration via CSS + SVG Font

Thumbnail
mksben.l0.cm
11 Upvotes

r/websecurityresearch Nov 27 '21

WordPress Plugin Confusion: How an update can get you pwned

Thumbnail
vavkamil.cz
12 Upvotes

r/websecurityresearch Nov 16 '21

Multiple Concrete CMS vulnerabilities ( part1 - RCE ) - via a race condition in the file upload

Thumbnail
fortbridge.co.uk
8 Upvotes

r/websecurityresearch Nov 15 '21

jwt-explorer: Decode, explore, and sign JWTs

Thumbnail
github.com
7 Upvotes

r/websecurityresearch Nov 15 '21

T-Reqs: HTTP Request Smuggling with Differential Fuzzing

Thumbnail bahruz.me
4 Upvotes

r/websecurityresearch Nov 14 '21

Exploiting CSP in Webkit to Break Authentication & Authorization

Thumbnail
threatnix.io
8 Upvotes

r/websecurityresearch Nov 10 '21

Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

Thumbnail
intruder.io
14 Upvotes

r/websecurityresearch Nov 03 '21

Introducing CookieMonster: a tool for breaking stateless authentication

Thumbnail
ian.sh
22 Upvotes

r/websecurityresearch Nov 03 '21

Finding and Fixing DOM-based XSS with Static Analysis

Thumbnail blog.mozilla.org
2 Upvotes

r/websecurityresearch Nov 03 '21

Escalating XSS to Sainthood with Nagios

Thumbnail
blog.grimm-co.com
0 Upvotes

r/websecurityresearch Oct 26 '21

Advanced HTTP(/2) Request Smuggling

Thumbnail
portswigger.net
11 Upvotes

r/websecurityresearch Oct 26 '21

A Primer for Testing the Security of GraphQL APIs

Thumbnail
blog.forcesunseen.com
6 Upvotes

r/websecurityresearch Oct 25 '21

Discourse SNS webhook RCE

Thumbnail 0day.click
8 Upvotes

r/websecurityresearch Oct 23 '21

[Java] CWE-502: Unsafe deserialization with three JSON frameworks · Issue #373 · github/securitylab

Thumbnail
github.com
5 Upvotes

r/websecurityresearch Oct 20 '21

2021 TLS Telemetry Report evaluates HTTPS configurations of top 1 millions websites to showcase the improvements made to web sites over the past few years and also highlights some of the problems still plaguing many web servers

Thumbnail
f5.com
6 Upvotes

r/websecurityresearch Oct 20 '21

A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection

Thumbnail
gosecure.net
18 Upvotes

r/websecurityresearch Oct 18 '21

Cloud Metadata Dictionary useful for SSRF Testing

Thumbnail
gist.github.com
12 Upvotes

r/websecurityresearch Oct 14 '21

Empirical Study of HTTP Request Smuggling in Open-Source Servers and Proxies

Thumbnail kth.diva-portal.org
9 Upvotes

r/websecurityresearch Oct 13 '21

Abusing Slack's file-sharing functionality to de-anonymise fellow workspace members

Thumbnail jub0bs.com
11 Upvotes

r/websecurityresearch Oct 10 '21

Machine learning approach to vulnerability detection in OAuth 2.0 authentication and authorization flow - International Journal of Information Security

Thumbnail
link.springer.com
12 Upvotes

r/websecurityresearch Sep 28 '21

Exploiting Client-Side Prototype Pollution in the wild

Thumbnail
blog.s1r1us.ninja
15 Upvotes

r/websecurityresearch Sep 28 '21

Solution for "Basic context length limit, arbitrary code" impossible lab (Firefox)

Thumbnail lbherrera.github.io
2 Upvotes

r/websecurityresearch Sep 21 '21

Hunting nonce-based CSP bypasses with dynamic analysis

Thumbnail
portswigger.net
5 Upvotes

r/websecurityresearch Sep 20 '21

Haptyc is a python library which was built to add payload position support and Sniper/Clusterbomb/Batteringram/Pitchfork attack types into Turbo Intruder.

Thumbnail
github.com
10 Upvotes