web-security

Tag

Cards List
#web-security

Cross-Site Scripting (XSS) Cheat Sheet

Lobsters Hottest ↗ · 3d ago Cached

This article is a Cross-Site Scripting (XSS) cheat sheet providing various techniques and code examples for executing XSS attacks, along with browser compatibility information, sourced from PortSwigger.

0 favorites 0 likes
#web-security

Serious editors are a commitment (at least for me)

Lobsters Hottest ↗ · 6d ago Cached

The article discusses the challenges of blocking old browser user-agents to reduce crawler load and provides specific notes for feed readers and archival services affected by these measures.

0 favorites 0 likes
#web-security

Getting the Anubis screen with every click

Lobsters Hottest ↗ · 2026-09-15 Cached

A user reports encountering the Anubis bot protection screen with every click on Lobsters, suggesting a recent change that disrupts user experience.

0 favorites 0 likes
#web-security

DeCloudflare

Hacker News Top ↗ · 2026-09-11 Cached

DeCloudflare is a project hosted on GitLab that provides tools to bypass or interact with Cloudflare services.

0 favorites 0 likes
#web-security

What's in a tag name? JavaScript, apparently

Lobsters Hottest ↗ · 2026-08-26 Cached

Research article from PortSwigger demonstrating new XSS attack vectors using JavaScript properties in HTML tag names, enabling WAF bypasses across browsers.

0 favorites 0 likes
#web-security

Inaudible sounds used to fingerprint browsers catch AliExpress red-handed

Ars Technica ↗ · 2026-08-24 Cached

AliExpress was found using inaudible sounds for browser fingerprinting, a technique that browsers like Firefox have fixed through library changes. The article discusses the use of multiple tracking methods and the ongoing privacy battle between websites and browser developers.

0 favorites 0 likes
#web-security

Show HN: GlassBox – what the browser reveals, and how identifiable you are

Hacker News Top ↗ · 2026-08-24 Cached

GlassBox is a client-side browser tool that reveals what data websites can collect about you through fingerprinting, running mostly locally to demonstrate privacy implications.

0 favorites 0 likes
#web-security

@rammcodes: Wait WTF? You can find all the subdomains of a website with one simple URL. This "CRT" hack lets you list subdomains as…

X AI KOLs Timeline ↗ · 2026-08-22 Cached

A simple URL using public certificate data can list all subdomains of a primary domain without any installation or setup.

0 favorites 0 likes
#web-security

Remotely Unlocking Electric Scooters

Hacker News Top ↗ · 2026-08-21 Cached

A security researcher details the process of remotely unlocking electric scooters by performing reconnaissance on the company's web infrastructure and exploiting vulnerabilities in WordPress and an operations panel.

0 favorites 0 likes
#web-security

@seclink: JSEF v1.10.0 is out A model-agnostic LLM eval toolchain + 20+ new hard vulnerability samples. Swap any OpenAI/Anthropic…

X AI KOLs Following ↗ · 2026-08-21 Cached

JSEF v1.10.0 is a model-agnostic LLM evaluation toolchain released with 20+ new hard vulnerability samples, designed for assessing LLMs in Java and web security contexts.

0 favorites 0 likes
#web-security

Detecting scraper bots through scroll behaviour

Hacker News Top ↗ · 2026-08-20 Cached

The article discusses using scroll behavior patterns to detect scraper bots by analyzing burstiness and memory metrics from human activity, improving on previous timing-based methods.

0 favorites 0 likes
#web-security

The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop

Wired ↗ · 2026-08-05 Cached

Security researcher James Kettle presented findings at Black Hat showing that while agentic AI is limited in autonomously devising novel hacks, it becomes a powerful partner when guided by humans, leading to the discovery of a new vulnerability class called Shared-Parser Confusion.

0 favorites 0 likes
#web-security

Web security is too hard

Hacker News Top ↗ · 2026-08-04 Cached

Eric Lawrence critiques Cloudflare's new Wallet signup flow, noting how it closely resembles consent phishing attacks, illustrating why web security is difficult.

0 favorites 0 likes
#web-security

Trusted URLs via Cryptographic Signatures

Hacker News Top ↗ · 2026-07-30 Cached

Certisfy introduces a feature that allows users to cryptographically sign URLs, enabling verification of link trustworthiness to combat fraud and misinformation in an AI-saturated online space.

0 favorites 0 likes
#web-security

Backstage access: an unauthenticated SQL injection in Front Gate Tickets

Lobsters Hottest ↗ · 2026-07-06 Cached

A security researcher discovered an unauthenticated SQL injection vulnerability in Front Gate Tickets' device API, allowing full database read and admin access to the ticketing platform for major US festivals.

0 favorites 0 likes
#web-security

Caught a .git/config crawler

Lobsters Hottest ↗ · 2026-07-06 Cached

The author describes how their honeypot website caught a .git/config crawler by serving fake git repository data, and analyzes Apache logs showing heavy crawling activity from a single IP address.

0 favorites 0 likes
#web-security

Web Security docs on MDN

Lobsters Hottest ↗ · 2026-07-06 Cached

Open Web Docs, funded by the Sovereign Tech Agency, has completed major updates to the Web Security documentation on MDN, covering attacks, defenses, threat modeling, and authentication, with plans for further privacy docs.

0 favorites 0 likes
#web-security

Web-based cryptography is always snake oil

Hacker News Top ↗ · 2026-07-05 Cached

The article argues that web-based end-to-end encryption is inherently insecure because the server distributing the client code can push malicious updates, making the threat model incoherent. It criticizes services like WhatsApp and Signal for similar flaws.

0 favorites 0 likes
#web-security

@apivixtls: Now let me recommend an open-source project. If you're interested in web penetration and API packet capture, you can use this directly. This project boils down to one thing: helping you do less manual work and focus on results. What exactly does it do? Your usual packet capture goes like: Open Charles / mitmproxy → a bunch of requests → you slowly sift through them…

X AI KOLs Timeline ↗ · 2026-06-30 Cached

Recommend an open-source web penetration and API packet capture analysis tool that uses AI to automatically filter, analyze requests, handle encryption, and generate analysis summaries and reproduction steps, greatly improving reverse engineering efficiency.

0 favorites 0 likes
#web-security

Don't verify email addresses by sending spam to them

Hacker News Top ↗ · 2026-06-23 Cached

The article criticizes a website (Pangram) for validating email addresses by sending a spam email to the entered address, highlighting a poor and deceptive practice in email verification.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback