Загрузка видео...
Не удалось загрузить видео
Somehow, Chrome 130+ started parsing the hostname from javascript URLs again and this can be used for a constrained XSS 🤯 This was the second solution for the recent CTF challenge.
24,966 просмотров • 1 год назад •via X (Twitter)
Комментарии: 10

André Baptista1 год назад
Deeplinks could also be used in this CTF to leak the secret, e.g. evilapp://legit.ethiack.ninja

André Baptista1 год назад
Also, this doesn't work on Firefox

Francisco Neves1 год назад
I wonder if other Safari tricks are now working on Chrome as well

𝔐Ǿʄț𝔄𝕭𝔄 𝔖a𝔐𝖀ℛ𝔄𝕴1 год назад
intresting🧐

mobin1 год назад
good tip, thanks for sharing this content😍

payphone1 год назад
What is the box with the countdown timer thing in it, on the left?

André Baptista1 год назад
It's just

YmV2ZW4K==1 год назад
How were you selecting the versions is it a plugin or feature?

André Baptista1 год назад
Check @browserling!

Alex Roqo1 год назад
Very interesting
Похожие видео
0:35
Sensitive content
#8 Laying on Lindsey and Camilla's laps ... and getting smooshed July challenge for a small video project a day. I should've just used the second from yesterday as this one :D I'm a glutton for ~~inflation via bubblegum~~... :D haha
Thiridian & Lindsey
34,398 просмотров • 1 год назад




