HNHacker News
TopNewBestAskShowJobs

albinowax_

691 karma · joined May 31, 2016

I research novel web attack techniques. More details at https://jameskettle.com/
submissionscomments

Drag and Pwnd: Exploiting VS Code with ASCII

portswigger.net·1 pts·albinowax_·
0

Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information

embracethered.com·4 pts·albinowax_·
0

Chaining Three Bugs to Access All Your ServiceNow Data

assetnote.io·2 pts·albinowax_·
0

ORM Leak Vulnerabilities

elttam.com·1 pts·albinowax_·
0

Hacking millions of modems and investigating who hacked my modem

samcurry.net·838 pts·albinowax_·
271

Getting XXE in Web Browsers Using ChatGPT

swarm.ptsecurity.com·1 pts·albinowax_·
0

Response Filter Denial of Service: shut down a website by triggering WAF rule

blog.sicuranext.com·95 pts·albinowax_·
26

Source Code Disclosure in Asp.net via Cookieless Sessions

swarm.ptsecurity.com·1 pts·albinowax_·
0

ChatGPT Account Takeover via Wildcard Web Cache Deception

nokline.github.io·4 pts·albinowax_·
0

Detection and Exploitation of Ivanti's Pulse Connect Secure RCE

assetnote.io·1 pts·albinowax_·
0

The curl quirk that exposed Burp Suite and Google Chrome

portswigger.net·1 pts·albinowax_·
1

Remote code execution in Homebrew by compromising the official Cask repository

blog.ryotak.me·4 pts·albinowax_·
0

Brave browser’s Tor feature found to leak .onion queries to ISPs

portswigger.net·2 pts·albinowax_·
0

Cracking reCAPTCHA, Turbo Intruder Style

portswigger.net·1 pts·albinowax_·
0

The age of browser XSS filters is over

portswigger.net·3 pts·albinowax_·
0

Significant new web hacking techniques from 2018

portswigger.net·1 pts·albinowax_·
0

Abusing Meta Programming for Unauthenticated RCE in Jenkins

blog.orange.tw·1 pts·albinowax_·
0

Turbo Intruder: Embracing the Billion-Request Attack

portswigger.net·2 pts·albinowax_·
0

An overview of the top web hacking techniques of 2017

portswigger.net·144 pts·albinowax_·
11

Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirects great

blog.bentkowski.info·2 pts·albinowax_·
0

Exploiting Open-XChange with Blind XXE via Powerpoint Files

hackerone.com·1 pts·albinowax_·
0

Detecting Same-Origin Redirections with a Bug in Firefox's CSP Implementation

diary.shift-js.info·1 pts·albinowax_·
0

Cloudflare, Fastly, Mozilla and Apple Working on SNI Encryption for TLS 1.3

tools.ietf.org·3 pts·albinowax_·
0

Evading CSP with DOM-based dangling markup

portswigger.net·1 pts·albinowax_·
0

XSS protection disappears from Microsoft Edge

portswigger.net·1 pts·albinowax_·
0

Server-Side Spreadsheet Injection – Formula Injection to Remote Code Execution

bishopfox.com·2 pts·albinowax_·
0

What website are you really on? Edge zero-day leaves users with no clue

portswigger.net·2 pts·albinowax_·
0

CSS-in-JS security issues

reactarmory.com·2 pts·albinowax_·
0

JSON hijacking for the modern web

blog.portswigger.net·3 pts·albinowax_·
0

Exploiting CORS Misconfigurations for Bitcoins and Bounties

blog.portswigger.net·1 pts·albinowax_·
0
Page 1 of 2Next →