I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer!
The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below:
https://t.co/nY20Anz0VO
(and thanks @garethheyes for making Shazzer!)
New research just dropped by @alien2exe on hijacking OAuth popups via predictable window. open() targets.
The chain uses iframe name collision forcing the auth flow into a controlled context, eventually linking an attacker-controlled addon to leak workspace PII and config data
https://t.co/GbimNCyqxx
New research just dropped by @alien2exe on hijacking OAuth popups via predictable window. open() targets.
The chain uses iframe name collision forcing the auth flow into a controlled context, eventually linking an attacker-controlled addon to leak workspace PII and config data
https://t.co/GbimNCyqxx
Last week I had the privilege of joining NullHat the first live hacking event of its kind in Morocco hosted by UM6P University Mohammed VI Polytechnic and 1337 Coding School and organized by The Elites' Security in collaboration with HackerOne.
Huge thanks to the organizers