Marcel SIneM(S)US · @simsus
226 followers · 5650 posts · Server social.tchncs.de

Schwere Lücken in Protons Web-App gefunden und gestopft - inside-it.ch inside-it.ch/schwere-luecken-i

#crosssitescripting #xss

Last updated 1 year ago

Mr.Trunk · @mrtrunk
12 followers · 19941 posts · Server dromedary.seedoubleyou.me
Aaron🏳️‍🌈 · @Aaron
92 followers · 798 posts · Server troet.cafe

Now that is called they should also bring back (Cross Site Scripting)

#xss #x #twitter

Last updated 1 year ago

tulpa · @tulpa
539 followers · 603 posts · Server fosstodon.org

I often wonder what are lurking in 's frontend. Like, some kind of or other injection you could write in a post, and it would run on anyone who viewed it. And now that we can follow hashtags, it's so much worse: just add a popular hashtag to your attack post and it'll get in front of lots of people who've never heard of you.

#vulnerabilities #mastodon #xss

Last updated 1 year ago

electronichien · @electronichien
59 followers · 422 posts · Server piaille.fr

La version anti-système-d'exploitation du pour les connaisseuses 😉

#xss

Last updated 1 year ago

barefootstache · @barefootstache
108 followers · 981 posts · Server qoto.org

(19/25)

Did you know that most newsletters have a or option? The benefit of RSS over a is that you are on the more private side, since lots of individuals use their private and lots of forms even ask for your name. This (if ever leaked) provides attackers a great data packet to put on their lists and once on such a list, it is hard to get off it.

One could argue on the other side that RSS is also not safe, since one is prone towards attacks, though this can be said of anything that has internet access. So one wouldn’t be better off if using email.

Thus when choosing a client, either for email or RSS feed, it is always better to opt for one that is not in the browser and sanitizes the message(s). Browser extensions are definitely a more lucrative attack option over operating system apps.

#security #DailyBloggingChallenge #rss #atom #newsletter #email #spam #xss #privacy

Last updated 1 year ago

Mr.Trunk · @mrtrunk
5 followers · 10982 posts · Server dromedary.seedoubleyou.me

SecurityOnline: XSSer – From XSS to RCE securityonline.info/xsser-xss-

#webexploitation #xsser #rce #xss

Last updated 1 year ago

Doug Parker · @develwithoutacause
233 followers · 896 posts · Server techhub.social

We just released a fix for a bug that could potentially cause an vulnerability in the library that uses for CSS inlining.

If you're using with Angular v16.1+, please update Angular and Critters.

For more details:
blog.angular.io/notice-of-xss-

#xss #critters #angular #ssr #universal

Last updated 1 year ago

tulpa · @tulpa
524 followers · 483 posts · Server fosstodon.org

For instance, I sub to SMBC comics. I don't allow smbc-comics.com in NoScript, but the interactive button on the comic page worked.

Eventually I realized that NewsBlur is apparently inlining the remote content and running it as if it were local to the app.

That basically means that is not just vulnerable to , but deliberately abusing it to implement one of its features. Super dangerous.

Having seen that, I can no longer consider using NewsBlur.

2/2

#newsblur #xss

Last updated 1 year ago

tulpa · @tulpa
524 followers · 481 posts · Server fosstodon.org

I guess that if the only thing I log into in my mobile browser is my feed reader, I don't have too much to fear there about or . Nobody is going to attack it, because there's no value in it. And it can't be used to steal anything else, because there isn't anything else.

#xss #csrf

Last updated 1 year ago

tulpa · @tulpa
523 followers · 446 posts · Server fosstodon.org

, like most cloud-based password managers, has a web vault.Imagine a stored on that. All your passwords stolen.

Thankfully, you probably aren't viewing untrusted content if you're an individual user (you put the data in yourself and now you're getting it back out). But for organization users, where you can see things created by someone else on your subscription? That could be possible.

#bitwarden #xss

Last updated 1 year ago

Mr.Trunk · @mrtrunk
5 followers · 8382 posts · Server dromedary.seedoubleyou.me
tulpa · @tulpa
523 followers · 406 posts · Server fosstodon.org

Imagine if there was a stored vulnerability in . A bad guy would send a Gmail user a malicious email with some JS in it, and when you open the message, the script would run. It could read your Google login cookie and send it to the bad guy. Then they would take over your Google account. Just think of the carnage.

#xss #gmail

Last updated 1 year ago

tulpa · @tulpa
520 followers · 400 posts · Server fosstodon.org

You know, if we really want to cut down on vulnerabilities, we need to quit putting a comment section on every dang site. Because the common case is user-submitted content that's rendered for a different user to view.

#xss #infosec

Last updated 1 year ago

ITSEC News · @itsecbot
1382 followers · 36109 posts · Server schleuss.online

Zimbra Collaboration Suite warning: Patch this 0-day right now (by hand)! - Zimbra didn't actually say, "Do not delay/Do it today," but they did say, "We kindly requ... nakedsecurity.sophos.com/2023/

#xss #zimbra #zeroday #dataloss #vulnerability

Last updated 1 year ago

Mr.Trunk · @mrtrunk
3 followers · 4049 posts · Server dromedary.seedoubleyou.me

SecurityWeek: Hackers Target Reddit Alternative Lemmy via Zero-Day Vulnerability securityweek.com/hackers-targe @news@lemmy.seedoubleyou.me

#vulnerabilities #lemmy #xss

Last updated 1 year ago

casey is remote · @realcaseyrollins
346 followers · 16073 posts · Server social.freetalklive.com

So apparently collapsed and all federation is broken? A bit confused about the situation and why that would affect federation tho

#lemmy #xss

Last updated 1 year ago

Leo :elixir: · @shooboo
14 followers · 30 posts · Server hachyderm.io

Several instances have been due to an XSS vulnerability around custom emojis.

lemmy.world/post/1293336

The fix is underway and everything will be fine - technically. Now it’s interesting to find out if this has any legal consequences. Does running a social media node as a hobby project turn out to be more of a liability than anything else?

#lemmy #hacked #infosec #xss

Last updated 1 year ago

Tarnkappe.info · @tarnkappeinfo
2311 followers · 4706 posts · Server social.tchncs.de