Anand Pilania :verified: · @AnandPilania
26 followers · 63 posts · Server phpc.social
Gioxx · @gioxx
157 followers · 617 posts · Server mastodon.uno
magikh0e :valid: · @magikh0e
145 followers · 157 posts · Server infosec.exchange

Before reporting , try turning it into an RCE

-XSS? try making an chain with

Persistent , chain with

#bugbountytip #ssrf #self #exploit #clickjacking #xss #csrf

Last updated 2 years ago

ITSEC News · @itsecbot
856 followers · 32559 posts · Server schleuss.online

Mild monthly security update from Firefox – but update anyway - You're probably thinking we're going to say, "Don't delay/Do it today"... and that's exac... nakedsecurity.sophos.com/2022/

#mozilla #firefox #clickjacking #vulnerability

Last updated 2 years ago

The Hacker News · @thehackernews
402 followers · 2779 posts · Server social.tchncs.de
Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

As of now, of browser extension UI is a big unsolved problem. Firefox originally had ways to display trusted UI in the content area, but with Chrome's extension model this possibility is gone now. The only way is leaving any non-trivial actions out of content area.

#clickjacking

Last updated 5 years ago

Yellow Flag · @WPalant
651 followers · 2784 posts · Server infosec.exchange

Saw a browser extension use some fairly sophisticated approach to prevent of its UI, protecting own frames from manipulations and disabling frames injected by the website. Of course, if you look closely this protection is also easily circumvented.

#clickjacking

Last updated 5 years ago