Manuel Caballero (@magicmac2000) 's Twitter Profile
Manuel Caballero

@magicmac2000

Independent Security Researcher.
Perpetual Student of Life :)

ID: 23310047

linkhttps://www.brokenbrowser.com calendar_today08-03-2009 14:01:02

210 Tweet

3,3K Takipçi

59 Takip Edilen

Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

UXSS/SOP bypass on IE: more adventures in a domainless world, thanks to incomplete and non-backported patches. 🤔😬 brokenbrowser.com/uxss-ie-domain…

UXSS/SOP bypass on IE: more adventures in a domainless world, thanks to incomplete and non-backported patches. 🤔😬

brokenbrowser.com/uxss-ie-domain…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge Referrer Spoof - How to spoof the referrer even after MS patch. 😱(also, inject an iframe everywhere) 😬 brokenbrowser.com/referer-spoofi…

MS Edge Referrer Spoof - How to spoof the referrer even after MS patch. 😱(also, inject an iframe everywhere) 😬

brokenbrowser.com/referer-spoofi…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - Defeating the popUp blocker, the XSS filter and SuperNavigate with our fake ticket to the Intranet Zone 🤣 brokenbrowser.com/free-ticket-to…

MS Edge - Defeating the popUp blocker, the XSS filter and SuperNavigate with our fake ticket to the Intranet Zone 🤣
brokenbrowser.com/free-ticket-to…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

Microsoft Edge - Detecting Installed Extensions from JS A generic method that works without manifest cooperation. 🤣 brokenbrowser.com/microsoft-edge…

Microsoft Edge - Detecting Installed Extensions from JS
A generic method that works without manifest cooperation. 🤣

brokenbrowser.com/microsoft-edge…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - SOP bypass abusing of the reading mode view. Spoof the user! Courtesy of the read: pseudo-protocol 🤣😇 brokenbrowser.com/sop-bypass-abu…

MS Edge - SOP bypass abusing of the reading mode view.
Spoof the user! Courtesy of the read: pseudo-protocol 🤣😇

brokenbrowser.com/sop-bypass-abu…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

Another (different!) Microsoft Edge SOP bypass on the same week! 🤓😁 Bug hunter: I will blog on the weekend. Thanks for your patience!

Another (different!) Microsoft Edge SOP bypass on the same week! 🤓😁

Bug hunter: I will blog on the weekend. Thanks for your patience!
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - SOP bypass / UXSS - "Tweeting like Charles Darwin" 🤣 brokenbrowser.com/sop-bypass-uxs… One minute video: youtu.be/K3Ui3JxZGnE

MS Edge - SOP bypass / UXSS - "Tweeting like Charles Darwin" 🤣

brokenbrowser.com/sop-bypass-uxs…

One minute video: youtu.be/K3Ui3JxZGnE
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - UXSS/SOP bypass. A different method which brings us even more bugs other than UXSS. Blog once the previous ones (2) are patched🐢

MS Edge - UXSS/SOP bypass. A different method which brings us even more bugs other than UXSS.

Blog once the previous ones (2) are patched🐢
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

UXSS/SOP bypass in several programs that use the Trident engine. The IE Tab extension for Chrome is an example. youtube.com/watch?v=eDW287…

UXSS/SOP bypass in several programs that use the Trident engine. The IE Tab extension for Chrome is an example.

youtube.com/watch?v=eDW287…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

I didn't know that in Intranet Zone, Edge automatically opens xaml/xbap files out of the AppContainer. Interesting to jmp from Edge to IE.🐰

I didn't know that in Intranet Zone, Edge automatically opens xaml/xbap files out of the AppContainer. Interesting to jmp from Edge to IE.🐰
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - Spoofing the Malware Page was patched today *and bypassed* again. Spoof the user again! (1 byte change) 👎 cracking.com.ar/demos/edgesmar…

MS Edge - Spoofing the Malware Page was patched today *and bypassed* again. Spoof the user again! (1 byte change) 👎

cracking.com.ar/demos/edgesmar…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

The Intranet bug was patched, but both UXSS/SOP bypasses are still alive. Also another one is coming out soon. 👌 "Bounty" ends next week.

The Intranet bug was patched, but both UXSS/SOP bypasses are still alive. Also another one is coming out soon. 👌

"Bounty" ends next week.
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - UXSS/SOP bypass. [Open/Redirect/Data]. Steal cookies, passwords and more. brokenbrowser.com/sop-bypass-uxs… Video: youtube.com/watch?v=vO6LRO…

MS Edge - UXSS/SOP bypass. [Open/Redirect/Data]. Steal cookies, passwords and more.

brokenbrowser.com/sop-bypass-uxs…

Video: youtube.com/watch?v=vO6LRO…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

IE11 - popUp blocker bypass - Combined with zombie alerts? popUps from everywhere! cracking.com.ar/demos/iepopups/ Video: youtube.com/watch?v=GemH59…

IE11 - popUp blocker bypass - Combined with zombie alerts? popUps from everywhere!

cracking.com.ar/demos/iepopups/

Video: youtube.com/watch?v=GemH59…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

Microsoft Security Chrome 8 days later, Chrome is patched. Issue will become public soon [ bugs.chromium.org/p/chromium/iss… ] From MSRC? Just the default thanks message. 🐢👍

Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

If anyone "exploits" Edge in a sec. conf, demand her to open cmd.exe instead of calc.exe. The latter can be open without vulns at all.

If anyone "exploits" Edge in a sec. conf, demand her to open cmd.exe instead of calc.exe. The latter can be open without vulns at all.
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

IE11 - Find out where the user is going AND what she typed into the address-bar. brokenbrowser.com/revealing-the-… Video: youtube.com/watch?v=xyzd7P…

IE11 - Find out where the user is going AND what she typed into the address-bar.

brokenbrowser.com/revealing-the-…

Video: youtube.com/watch?v=xyzd7P…
Manuel Caballero (@magicmac2000) 's Twitter Profile Photo

MS Edge - Address Bar Spoof - cracking.com.ar/demos/edgespoo… Tested on: MS Edge 42.17134.1.0 Thanks Avinash, your question inspired me to test a bit and stumbled upon this bug.

MS Edge - Address Bar Spoof - cracking.com.ar/demos/edgespoo…

Tested on: MS Edge 42.17134.1.0

Thanks <a href="/knowledge_2014/">Avinash</a>, your question inspired me to test a bit and stumbled upon this bug.