Tweets
- Tweets
- Tweets & replies
- Media
@steike is blocked
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @steike.
-
Make your own colliding PDFs: https://alf.nu/SHA1
-
Posted four old browser bugs https://alf.nu/WebkitURLs and a new one https://alf.nu/SafariReaderUXSS …pic.twitter.com/izc4q9nkno
-
In progress. http://alf.nu/ReturnTrue and http://regex.alf.nu are back up, http://escape.alf.nu soon.https://twitter.com/soprano/status/801556616793362433 …
-
Oh hey, that's CVE-2011-3441! (except on iOS no extra tricks were needed, just 1.2.3.4%20.victim.㏄ and get cookies)https://twitter.com/SecurityMB/status/750422253209264129 …
-
It looks like the same solution should work in all the modern browsers with small modifications. This is surprising.https://twitter.com/securitymb/status/763852426541670401 …
-
Had a bunch of alert(1)-to-win levels left over that weren't really security related. General ecmascript golf time! http://alf.nu/ReturnTrue
-
@steike Psssht, don't tell anyone about `http://bla.com/%0 ` resulting in a 400 without headers! -
Is your entire domain 'X-Frame-Options: DENY', but not your error pages? Now's as good a time as any to fix it… (iframe UXSS in Safari)
-
We gave the whole internet keys so airport security won't break open your luggage. They do anyway. In other news, an FPGA dev kit is a bomb.
-
"Can you please provide me the last 4 characters of the cPanel password to verify ownership of the account?" -
@bluehost cc@thorsheim :-) -
Slides for my
@44CON talk about FireEye: https://www.ernw.de/download/ERNW_44CON_PlayingWithFire_signed.pdf …#playingwithfire -
console.close = function() { console.log('%c', 'background:url(/proxy/http/foo%bar.com/)') }
-
Do you like JSON? Good. Because XSS Puzzle 6 is out and it's about json2.js and ES6. http://kcal.pw/puzzle6.html Please re-tweet :)
-
@ehomakov Hi Egor, http://Booking.com uses SSL technology. Its certificate has been issued by Thawte. Regards, EK
-
How many ways can you steal this token in modern browsers? http://token.alf.nu/
-
Vendor that "fixed" account hijack CSRF last year by adding a token (but not checking it) has now removed the button; endpoint still there.
-
Next to "We escape \ and ", thus making it safe!", can we mention ${} and the RCE that got Yahoo/eBay?
@official_phppic.twitter.com/f1bVGz3bRe
-
Erling Ellingsen followed Project Zero Bugs, FutureCNN, Gábor Molnár and 128 others
-
@ProjectZeroBugs
Checks for new bug reports every 10 minutes. Not affiliated with Google. Ran by
@landaire -
-
-
.. And here it comes the second and more interesting
#XSS solution part: http://www.pwntester.com/blog/2014/01/08/escape-dot-alf-dot-nu-xss-challenges-write-ups-part-2/ …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Erling Ellingsen
.mario
Felix Wilhelm
File Descriptor
Booking.com
Alvaro Muñoz