Loading video...

Video Failed to Load

Go Home

Somehow, Chrome 130+ started parsing the hostname from javascript URLs again and this can be used for a constrained XSS 🤯 This was the second solution for the recent CTF challenge.

24,966 views • 1 year ago •via X (Twitter)

10 Comments

André Baptista's profile picture
André Baptista1 year ago

Deeplinks could also be used in this CTF to leak the secret, e.g. evilapp://legit.ethiack.ninja

André Baptista's profile picture
André Baptista1 year ago

Also, this doesn't work on Firefox

Francisco Neves's profile picture
Francisco Neves1 year ago

I wonder if other Safari tricks are now working on Chrome as well

𝔐Ǿʄț𝔄𝕭𝔄 𝔖a𝔐𝖀ℛ𝔄𝕴's profile picture
𝔐Ǿʄț𝔄𝕭𝔄 𝔖a𝔐𝖀ℛ𝔄𝕴1 year ago

intresting🧐

mobin's profile picture
mobin1 year ago

good tip, thanks for sharing this content😍

payphone's profile picture
payphone1 year ago

What is the box with the countdown timer thing in it, on the left?

André Baptista's profile picture
André Baptista1 year ago

It's just

YmV2ZW4K=='s profile picture
YmV2ZW4K==1 year ago

How were you selecting the versions is it a plugin or feature?

André Baptista's profile picture
André Baptista1 year ago

Check @browserling!

Alex Roqo's profile picture
Alex Roqo1 year ago

Very interesting

Related Videos