Let’s Encrypt has made IP-based TLS certificates generally available, allowing secure HTTPS connections directly to IP addresses.
https://t.co/X8b28mJXTV
#LetsEncrypt#Certificates#TLS#Security
Voting is now live for the top ten web hacking techniques of 2025! Grab a coffee, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques:
https://t.co/srZ9GhJgSN
I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below:
https://t.co/Tje8Ce8if0
I think many people are familiar with the topic of blind CSS exfiltration, especially after the post by
@garethheyes
However, an important update has occurred since then, which I wrote below ->
Somehow, Chrome 130+ started parsing the hostname from javascript URLs again and this can be used for a constrained XSS 🤯
https://t.co/wPeCdD6TVW
This was the second solution for the recent CTF challenge.
@garethheyes I was able to complete them :D (tested on Chrome)
Shift_JIS (0x81FC) https://t.co/8sOPq74IT3
GBK (0x81FD) https://t.co/EB1ZW2xzuM
gb18030 (0x81FE) https://t.co/D0qyIgRcVw
big5 (0xA15C) https://t.co/KoH4lBne6j
💡 Quick tip
💳 When testing checkout systems, always try to order with test cards!
Test cards are used by developers to simulate payments during development but they are sometimes still accepted in production!
A few test card combinations for 2Checkout / Stripe 👇