koto (@kkotowicz) 's Twitter Profile
koto

@kkotowicz

security ninja wannabe
Mastodon: @[email protected]

ID: 7863612

linkhttp://blog.kotowicz.net calendar_today01-08-2007 00:38:01

5,5K Tweet

8,8K Followers

401 Following

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

We are excited to announce the new Mobile VRP! We are looking for bughunters to help us find and fix vulnerabilities in our mobile applications. bughunters.google.com/about/rules/66…

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

'document.domain' will be immutable in Chrome 115. Thank you and congratulations to Mike West and his amazing team for making the web safer by deprecating legacy badness. It's great to see Chrome leading by example here. Hopefully others will follow. developer.chrome.com/blog/document-…

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

From June 1st 10:00 UTC to June 30th 10:00 UTC we will award a 75% bonus to any valid Gmail bug report. Get hacking!🤘 Rules: bughunters.google.com/about/rules/54…

koto (@kkotowicz) 's Twitter Profile Photo

One of the rougher edges of the platform that enables an xss vector is going away soon. This fixes xss many sites didnt ecen realize they had. Great body of work championed by Jun Kokatsu!

Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

Mastodon、RCEとXSSのセキュリティ修正があります。 それに関連してRubyの「sanitize」というgemのHTMLサニタイザーのバイパスも修正されています。 github.com/rgrove/sanitiz…

@securitymb@infosec.exchange (@securitymb) 's Twitter Profile Photo

So I'm starting a Youtube Channel 😄 Join me today at 19:00 CEST (in other words: in three hours) when I'll talk about 10 highlights from my bug hunting career: youtube.com/watch?v=utz3SH…

Jun Kokatsu (@shhnjk) 's Twitter Profile Photo

A few deprecations shipped in Chrome 120. Data URLs in SVG <use> is now blocked. chromestatus.com/feature/512882… CSP Embedded Enforcement's implicit opt-in for same-origin iframes is gone. chromestatus.com/feature/509815…

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

Mozilla has changed their standards position on Trusted Types to positive 🎉 2024 will be a bad year for DOM-based XSS. github.com/mozilla/standa…

koto (@kkotowicz) 's Twitter Profile Photo

See how Google's security engineering team handles rollouts at scale, so we can safely enforce Strict CSP, Trusted Types and other security features on 100s new services yearly. bughunters.google.com/blog/589651289…

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

Ever wondered how to increase your bug bounties 💸 ? Our latest blog post introduces our domain tiers security concept and how it is applied at Google, and includes a list of Google's highest sensitivity domains. bughunters.google.com/blog/456217538…

Michał Kowalczyk 🇺🇦 (@dsredford) 's Twitter Profile Photo

It's finally happened! NEWAG IP Management just sued us for copyright infringement and unfair competition. Here's a symbolic picture of the lawsuit as a whole: Newag quoting q3k's own code as supposedly their IP :) More: infosec.exchange/@q3k@hackerspa…

It's finally happened! NEWAG IP Management just sued us for copyright infringement and unfair competition.

Here's a symbolic picture of the lawsuit as a whole: Newag quoting q3k's own code as supposedly their IP :)

More: infosec.exchange/@q3k@hackerspa…
Gynvael Coldwind (@gynvael) 's Twitter Profile Photo

So NEWAG (context: media.ccc.de/v/37c3-12142-b…) finally filed a lawsuit against members of Dragon Sector / SPS. It took them a few months from when they said they'll do it, and apparently there were some snafus with addresses, but here we are. 1/n🧵

koto (@kkotowicz) 's Twitter Profile Photo

XSS in Gmail is now $20k (or 50% more for exceptional quality report). Good thing we don't have XSSes anymore.... Or do we? :)

Gynvael Coldwind (@gynvael) 's Twitter Profile Photo

If anyone is following the NEWAG vs Dragon Sector case, this article (in PL, but, well, 2024, google translate) is a really good read about the actual lawsuit and the first day of trial. Second day of trial will be on Jan 15, so there's some time for sides to file more stuff.

koto (@kkotowicz) 's Twitter Profile Photo

Pretty cool exploit chain with the redirects. The writeup is also excellent, and the "screenshots" being actually interactive? 🤯 Thanks a lot for the research, Rebane!