HNHacker News
TopNewBestAskShowJobs

Herrera

56 karma · joined December 11, 2015

Security researcher studying Computer Science at Federal University of Santa Catarina (UFSC).
submissionscomments
Herrera··on Why do we have both CSRF protection and CORS?
Yeah, https://xsleaks.dev tracks most of the known ways to leak cross-origin data.
Herrera··on Patch Critical Cryptographic Vulnerability in Microsoft Windows [pdf]
Bleichenbacher'06 never dies.
Herrera··on How I recorded user behaviour on my competitor’s websites
Interesting... I reported a variation of this issue to Google back in 2015 and they said they weren't "concerned about the premise of the attack in the bug description. You can always make the back button go to a page under your control by doing a second navigation, e.g., with pushState".
Herrera··on The Line of Death
I was playing with picture-in-picture attacks on Chrome some time ago and even proposed a way for mitigation, but it was dismissed.

Here's the PoC I did: https://www.youtube.com/watch?v=0oega6C5SF0

And the mitigation I proposed was from this: http://i.imgur.com/8m6UdiC.png

To this: http://i.imgur.com/turRAdc.png

Herrera··on Cursory hack – Fake address bar interaction
Really? That is strange, because there is ways this could be exploited... Can you link them to me?
Herrera··on Malware in the browser: how you might get hacked by a Chrome extension
A somewhat related topic:

A few months ago Google fixed a vulnerability on the inline installation. It was possible to start a install on the attacker's website and then redirect the page to an arbitrary one. This would confuse the user, making him believe that the install came from the arbitrary page.

Here is the PoC if anyone is interested (CVE-2016-1640): https://www.youtube.com/watch?v=f_9ObDqBoo8

Herrera··on A game made with CSS/HTML only
If you keep your left mouse button pressed you can cheat too.
Herrera··on Real-time GIF images
You are right. You receive one image containing a inspirational message for your family and decide to send to your family members. Then it changes to a image asking for money to be sent to an account because you are in need. I could see this working.
Herrera··on Waiting for an Employment-Based Green Card
Yes, if you invest at least $1,000,000 and employ more than 10 people for two years you will be eligible to the EB-5 visa. It seems a good way to get a green card if you have the money.
Herrera··on Google Wallet: Send money via text message
Thank you! I got involved with the security world recently and I'm really enjoying it. And I would like to clarify myself, the comment I made earlier was a little ambiguous. The bug that got fixed only spoofs the omnibox and not the HTTPS lock. The others spoof both. That said, when I am able to disclose these vulnerabilities, I intend to write a post about them.
Herrera··on Google Wallet: Send money via text message
I already did report them. The first one was fixed (CVE-2015-6782), got $1k from Google. There are three more they are working on.
Herrera··on Google Wallet: Send money via text message
It is not always enough. For example, recently I have found several ways to spoof the URL and HTTPS lock on Google Chrome. So phishing seems to be a concern.