
kunte_
@kunte_ctf
CTF Player with @FluxFingers | Ph.D. Student
ID: 40940265
18-05-2009 19:01:16
224 Tweet
263 Followers
251 Following


#GoogleCTF is over! This year I prepared a race-condition based challenge which was a combination of #xsleaks #xss and other interesting client-side bugs. The challenge was solved by 10 teams and had unintended solutions, some of which are awesome! π gist.github.com/terjanq/7c1a71β¦



The Hacklu 2022 CTF is over! Thank you for playing! Of course special congrats to the top 3 teams! π₯³ π π₯ organizers π₯ justCatTheFish π₯ π¦ CTF: flu.xxx Challenges will still be up for a while. See you next Year! #hacklu #ctf FluxFingers


Helped justCatTheFish with yet another ctf and solved two highest scored challenges: HTPL from BitK and foodAPI from kunte_. The former was a JS sandbox escape and the latter was about 0day in #denodb. Some useful tricks π gist.github.com/terjanq/1926a1β¦ #hacklu FluxFingers



Our paper "Finding All Cross-Site Needles in the DOM Stack - A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers" got accepted at ACM CCS 2023! ACM CCS 2024 The camera-ready version will be available at sigsac.org/ccs/CCS2023. Tool will be on GitHub.




Can server-side scanning research be legal and ethical? For our upcoming IEEE S&P paper "Where are the red lines?" we talked to experts on law and ethics, and web operators. We discussed challenges, solutions and various fictional research scenarios. swag.cispa.saarland/papers/hantke2β¦




