Video wird geladen...
Video konnte nicht geladen werden
Somehow, Chrome 130+ started parsing the hostname from javascript URLs again and this can be used for a constrained XSS 🤯 This was the second solution for the recent CTF challenge.
24,966 Aufrufe • vor 1 Jahr •via X (Twitter)
10 Kommentare

André Baptistavor 1 Jahr
Deeplinks could also be used in this CTF to leak the secret, e.g. evilapp://legit.ethiack.ninja

André Baptistavor 1 Jahr
Also, this doesn't work on Firefox

Francisco Nevesvor 1 Jahr
I wonder if other Safari tricks are now working on Chrome as well

𝔐Ǿʄț𝔄𝕭𝔄 𝔖a𝔐𝖀ℛ𝔄𝕴vor 1 Jahr
intresting🧐

mobinvor 1 Jahr
good tip, thanks for sharing this content😍

payphonevor 1 Jahr
What is the box with the countdown timer thing in it, on the left?

André Baptistavor 1 Jahr
It's just

YmV2ZW4K==vor 1 Jahr
How were you selecting the versions is it a plugin or feature?

André Baptistavor 1 Jahr
Check @browserling!

Alex Roqovor 1 Jahr
Very interesting
Ähnliche Videos
0:35
Sensitive content
#8 Laying on Lindsey and Camilla's laps ... and getting smooshed July challenge for a small video project a day. I should've just used the second from yesterday as this one :D I'm a glutton for ~~inflation via bubblegum~~... :D haha
Thiridian & Lindsey
34,191 Aufrufe • vor 1 Jahr




