Sebastian Lekies

@slekies

Tech Lead - Web Application Security Scanning

Pridružio/la se listopad 2011.

@slekies je blokiran/a

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika @slekies.

  1. Prikvačeni tweet
    5. sij

    The full list of CSP bypasses with all known vectors that came up during the recent discussions:

  2. 19. sij

    Advice to untangle cyber PR: If someone says "we got attacked X times" without exactly saying what "attack" means it's cyber-bullshit.

  3. 18. sij

    We keep hearing rumors that there'll be an ★Allstars 2017★ during OWASP AppSec EU in Belfast. Maybe there is something to it… cc

  4. 17. sij
  5. 12. sij
  6. 12. sij

    How to write a research paper: a guide for software engineers & practitioners. /cc

  7. 10. sij

    Remove DOM nodes without JavaScript: <svg><animate id=a dur=1 /><circle r=100> <discard begin=a.end xlink:href= /><style id=x>*{fill:red}

  8. 7. sij
  9. 7. sij

    5 more CSP bypasses added to the list:

  10. 6. sij

    any additional ideas?

  11. 6. sij

    Framework-specific bypasses are also welcome!

  12. 6. sij

    Added a few more CSP bypasses to the list. Happy to receive suggestions, ideas and PoCs. Just ping me.

  13. 5. sij
  14. 5. sij

    CSP-protected HTML injections can probably be used to break same-site cookies to conduct CSRF. (cc , , )

  15. 28. pro 2016.
  16. 2. sij

    Slightly surprised by how many ways there are to mutate HTML without JS! (by )

  17. 1. sij

    hah, my CSP nonce bypass:

  18. 31. pro 2016.

    Another type of CSP nonce bypass. FF+Chrome. Works with traditional reflected XSS. Happy new year!

  19. Sebastian Lekies počeo/la je pratiti , , and 4 others
    • @intenttoship

      I tweet when browser makers announce their intent to ship, change or remove features in their web engines! I was made by .

  20. 29. pro 2016.

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·