koto Profile
koto

@kkotowicz

Followers
9K
Following
4K
Media
81
Statuses
6K

security ninja wannabe Mastodon: @[email protected]

Joined August 2007
Don't wanna be here? Send us removal request.
@kkotowicz
koto
8 months
RT @GoogleVRP: We're sending a HUGE thank you to our incredible community of bughunters ! 🙏 Your passion for finding vulnerabilities keeps….
0
38
0
@kkotowicz
koto
8 months
RT @Zaufana3Strona: Co do jasnej cholery żeby nie napisać dosadniej.
0
27
0
@kkotowicz
koto
9 months
RT @GoogleVRP: Do you want to learn more about the various Vulnerability Reward Programs offered by Google? Or you're looking for inspirati….
0
10
0
@kkotowicz
koto
10 months
Pretty cool exploit chain with the redirects. The writeup is also excellent, and the "screenshots" being actually interactive? 🤯. Thanks a lot for the research, @rebane2001!.
@albinowax
James Kettle
10 months
Love a good client-side exploit chain! This crazy cross-product chain targeting Google by @rebane2001 is a great example of the type of exploit that gets easier the longer you spend targeting a single company .
0
4
11
@kkotowicz
koto
11 months
RT @gynvael: If anyone is following the NEWAG vs Dragon Sector case, this article (in PL, but, well, 2024, google translate) is a really go….
0
16
0
@kkotowicz
koto
1 year
XSS in Gmail is now $20k (or 50% more for exceptional quality report). Good thing we don't have XSSes anymore. Or do we? :).
@GoogleVRP
Google VRP (Google Bug Hunters)
1 year
🚨💰 Google VRP Reward Update 💰🚨 Good news, we are significantly increasing the reward amounts offered by the Google VRP! Look out for up to 5x higher payouts and a maximum reward of $151,515! Details here:.
1
6
58
@kkotowicz
koto
1 year
RT @dsredford: It's finally happened! NEWAG IP Management just sued us for copyright infringement and unfair competition. Here's a symboli….
0
78
0
@kkotowicz
koto
1 year
RT @gynvael: So NEWAG (context: finally filed a lawsuit against members of @DragonSectorCTF / SPS. It took them a….
0
20
0
@kkotowicz
koto
1 year
RT @we1x: @LinkedIn says no to DOM XSS by enforcing Trusted Types! Congratulations to @shafigullin for this achievement 🎉.
0
4
0
@kkotowicz
koto
1 year
RT @m_gol: @kkotowicz It took us a while but jQuery 4.0.0 beta is out now:
0
1
0
@kkotowicz
koto
2 years
See how Google's security engineering team handles rollouts at scale, so we can safely enforce Strict CSP, Trusted Types and other security features on 100s new services yearly.
Tweet card summary image
bughunters.google.com
There are vastly more engineers at Google dedicated to creating and maintaining new products than there are security engineers working to secure products. For this reason, Google security has to...
1
38
74
@kkotowicz
koto
2 years
RT @TheRegister: Mozilla decides Trusted Types is a worthy security feature
Tweet card summary image
theregister.com
DOM-XSS attacks have become scarce on Google websites since TT debuted
0
11
0
@kkotowicz
koto
2 years
RT @shhnjk: A few deprecations shipped in Chrome 120. Data URLs in SVG <use> is now blocked. CSP Embedded Enforce….
0
7
0
@kkotowicz
koto
2 years
RT @SecurityMB: So I'm starting a Youtube Channel 😄 Join me today at 19:00 CEST (in other words: in three hours) when I'll talk about 10 hi….
0
23
0
@kkotowicz
koto
2 years
RT @kinugawamasato: Mastodon、RCEとXSSのセキュリティ修正があります。.それに関連してRubyの「sanitize」というgemのHTMLサニタイザーのバイパスも修正されています。.
Tweet card summary image
github.com
### Impact Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize `>= 3.0.0, < 6.0.2` when Sanitize is configured to use the built-in "...
0
14
0
@kkotowicz
koto
2 years
RT @greg16676935420: AI vs Mayonnaise
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
1K
0
@kkotowicz
koto
2 years
RT @we1x: 🥳 This will make using side-channel techniques such as Timing Attacks, XS-Leaks, and COSI harder!.
0
3
0