Video yükleniyor...
Video Yüklenemedi
Somehow, Chrome 130+ started parsing the hostname from javascript URLs again and this can be used for a constrained XSS 🤯 This was the second solution for the recent CTF challenge.
24,966 görüntüleme • 1 yıl önce •via X (Twitter)
10 Yorum

André Baptista1 yıl önce
Deeplinks could also be used in this CTF to leak the secret, e.g. evilapp://legit.ethiack.ninja

André Baptista1 yıl önce
Also, this doesn't work on Firefox

Francisco Neves1 yıl önce
I wonder if other Safari tricks are now working on Chrome as well

𝔐Ǿʄț𝔄𝕭𝔄 𝔖a𝔐𝖀ℛ𝔄𝕴1 yıl önce
intresting🧐

mobin1 yıl önce
good tip, thanks for sharing this content😍

payphone1 yıl önce
What is the box with the countdown timer thing in it, on the left?

André Baptista1 yıl önce
It's just

YmV2ZW4K==1 yıl önce
How were you selecting the versions is it a plugin or feature?

André Baptista1 yıl önce
Check @browserling!

Alex Roqo1 yıl önce
Very interesting
Benzer Videolar
0:35
Sensitive content
#8 Laying on Lindsey and Camilla's laps ... and getting smooshed July challenge for a small video project a day. I should've just used the second from yesterday as this one :D I'm a glutton for ~~inflation via bubblegum~~... :D haha
Thiridian & Lindsey
34,191 görüntüleme • 1 yıl önce




