Tag
This article is a Cross-Site Scripting (XSS) cheat sheet providing various techniques and code examples for executing XSS attacks, along with browser compatibility information, sourced from PortSwigger.
The article discusses the challenges of blocking old browser user-agents to reduce crawler load and provides specific notes for feed readers and archival services affected by these measures.
A user reports encountering the Anubis bot protection screen with every click on Lobsters, suggesting a recent change that disrupts user experience.
DeCloudflare is a project hosted on GitLab that provides tools to bypass or interact with Cloudflare services.
Research article from PortSwigger demonstrating new XSS attack vectors using JavaScript properties in HTML tag names, enabling WAF bypasses across browsers.
AliExpress was found using inaudible sounds for browser fingerprinting, a technique that browsers like Firefox have fixed through library changes. The article discusses the use of multiple tracking methods and the ongoing privacy battle between websites and browser developers.
GlassBox is a client-side browser tool that reveals what data websites can collect about you through fingerprinting, running mostly locally to demonstrate privacy implications.
A simple URL using public certificate data can list all subdomains of a primary domain without any installation or setup.
A security researcher details the process of remotely unlocking electric scooters by performing reconnaissance on the company's web infrastructure and exploiting vulnerabilities in WordPress and an operations panel.
JSEF v1.10.0 is a model-agnostic LLM evaluation toolchain released with 20+ new hard vulnerability samples, designed for assessing LLMs in Java and web security contexts.
The article discusses using scroll behavior patterns to detect scraper bots by analyzing burstiness and memory metrics from human activity, improving on previous timing-based methods.
Security researcher James Kettle presented findings at Black Hat showing that while agentic AI is limited in autonomously devising novel hacks, it becomes a powerful partner when guided by humans, leading to the discovery of a new vulnerability class called Shared-Parser Confusion.
Eric Lawrence critiques Cloudflare's new Wallet signup flow, noting how it closely resembles consent phishing attacks, illustrating why web security is difficult.
Certisfy introduces a feature that allows users to cryptographically sign URLs, enabling verification of link trustworthiness to combat fraud and misinformation in an AI-saturated online space.
A security researcher discovered an unauthenticated SQL injection vulnerability in Front Gate Tickets' device API, allowing full database read and admin access to the ticketing platform for major US festivals.
The author describes how their honeypot website caught a .git/config crawler by serving fake git repository data, and analyzes Apache logs showing heavy crawling activity from a single IP address.
Open Web Docs, funded by the Sovereign Tech Agency, has completed major updates to the Web Security documentation on MDN, covering attacks, defenses, threat modeling, and authentication, with plans for further privacy docs.
The article argues that web-based end-to-end encryption is inherently insecure because the server distributing the client code can push malicious updates, making the threat model incoherent. It criticizes services like WhatsApp and Signal for similar flaws.
Recommend an open-source web penetration and API packet capture analysis tool that uses AI to automatically filter, analyze requests, handle encryption, and generate analysis summaries and reproduction steps, greatly improving reverse engineering efficiency.
The article criticizes a website (Pangram) for validating email addresses by sending a spam email to the entered address, highlighting a poor and deceptive practice in email verification.