HNHacker News
TopNewBestAskShowJobs

albertpedersen

246 karma · joined August 3, 2022

submissionscomments
albertpedersen··on CookieStore
Starting with Firefox 140, the Cookie Store API is a baseline feature: https://caniuse.com/cookie-store-api
albertpedersen··on Confused Deputy Vulnerability in Cloudflare CASB
This is the write-up of a critical vulnerability I discovered in Cloudflare CASB that enabled me to view sensitive information about other customers’ Microsoft and GitHub organizations, including employee names/emails, links to SharePoint files, private repository names/descriptions and more.
albertpedersen··on Cloudflare's handling of a bug in interpreting IPv4-mapped IPv6 addresses
Link to the report on HackerOne: https://hackerone.com/reports/1785260
albertpedersen··on Hijacking Email with Cloudflare Email Routing
The bug was initially reported to Cloudflare's private bug bounty program since there was no public program at the time. Like it or not, the private program does not have the same disclosure policy as the public program does.

In early July I asked if the report could be disclosed, seeing as things had changed since the bug was originally reported. Cloudflare agreed and the report was then moved to the public program. As to why it was disclosed now rather than in February when the public program launched, that was my fault for not asking earlier.

albertpedersen··on Hijacking Email with Cloudflare Email Routing
Yup, 'Burp' refers to the free version of 'Burp Suite'. I don't use Burp Suite anymore though. Some months ago I started using mitmproxy (https://github.com/mitmproxy/mitmproxy) due to it's Python scripting API. I have never looked back since then.
albertpedersen··on Hijacking Email with Cloudflare Email Routing
In this case the second $3000 bounty was due to a 2x promotion at the time. The guideline for a critical is $3000, but Cloudflare does occasionally award bonuses for severe vulnerabilities (e.g. https://hackerone.com/reports/1478633).
albertpedersen··on Hijacking Email with Cloudflare Email Routing
Here's the write-up of a simple but severe exploit I found in Cloudflare's email forwarding service.