Explore tweets tagged as #filedescriptor
Say hello to the Polyglot Payload. The complete payload for the XSS Polyglot Challengev2 is now available on the platform. Source: . Thanks @filedescriptor and crlf .#xss #polyglot #polyglotxss
6
42
271
Chrome extension that abuses Trusted Types to find DOMXSS! It works by logging the stack trace of all sink calls and their changes to the DOM. It helps you trace from sink to source and source to sink. ⚙⚙️. - #infosec #cybersec #bugbountytips
2
21
96
Want to start finding DOM-based vulnerabilities easily? 🤑. Check out Untrusted Types by @filedescriptor, a simple yet advanced web extension that can help you locate DOM sinks through the Trusted Types API! 🤠. Untrusted Types is available on Github!👇.
6
30
159
2⃣Untrusted Types by @filedescriptor. Untrusted Types web extension can help you locate DOM sinks through the Trusted Types API—an API that helps developers lock down certain DOM sinks that could potentially lead to DOM-based XSS vulnerabilities.
1
2
27
Say hello to the Polyglot Payload. The complete payload for the XSS Polyglot Challengev2 is now available on the platform. Source: . Thanks @filedescriptor and crlf . credit: @XssReport . #xss #BugBounty.
0
6
42
#10 Good old cookie tossing.Hijacking OAuth via cookie tossing: funny enough, twas my first client-side bug: Can an LLM come up with that? .AFAIK, @filedescriptor was the first to come up with many similar creative attacks.
2
0
22
One character, 5 digit bounties! 💰.This #BugBountyTip from @filedescriptor (@0xReconless) is a classic example of "think like a developer". 👇 #BugBountyTips #HackWithIntigriti
0
15
52
@Rhynorater @filedescriptor Shamelessly dropping related video . No Bounty for Open Redirects?! – ft. LiveOverflow. Article:
1
0
21
The panel vote for the Top ten web hacking techniques 2023 has now concluded! Massive thanks to @filedescriptor @irsdl @Agarri_FR for serving on the panel! Got some outstanding finalists in there. I'll get the results written up and published in the next day or two. 🥁.
6
9
122
@S1r1u5_ One of the coolest bugs I ever reported (that is public) was (with additional context provided in comment 52). Another incredibly creative bug was on how to leak cross-origin content with CSS and UTF-16 by @filedescriptor ( .
1
0
29
what happened to @filedescriptor? It's been long. Dude just disappeared. @Rhynorater @albinowax @LiveOverflow any idea.
2
0
4