Lil Endian (@lil_endian) 's Twitter Profile
Lil Endian

@lil_endian

Bugs for fun and profit. hackerone.com/lil_endian

ID: 1173696194616451073

linkhttps://asdf.foo calendar_today16-09-2019 20:34:08

59 Tweet

580 Followers

768 Following

Lil Endian (@lil_endian) 's Twitter Profile Photo

Abusing Yelps Cookie bridge to turn self XSS into plain XSS and leak HttpOnly cookies of the victim. I'm a little dissapointed with their CVSS scoring here. Another case of setting PR:L on a self signup service...

Lil Endian (@lil_endian) 's Twitter Profile Photo

Do you sometimes find that you'll get blocked by Cloudflare when you're proxying your browser through Burp, but not otherwise? Burp will default to HTTP/2 if the server supports it. Unchecking this option fixes the issue.

Do you sometimes find that you'll get blocked by Cloudflare when you're proxying your browser through Burp, but not otherwise? Burp will default to HTTP/2 if the server supports it. Unchecking this option fixes the issue.
Lil Endian (@lil_endian) 's Twitter Profile Photo

When did middle-click to pop a javascript: XSS with target="_blank" stop working in Chrome? I feel like this worked not that long ago. It still works in Firefox.

When did middle-click to pop a javascript: XSS with target="_blank" stop working in Chrome? I feel like this worked not that long ago. It still works in Firefox.
Lil Endian (@lil_endian) 's Twitter Profile Photo

This morning the trading platform Nordnet Danmark had an issue where users were getting randomly signed in to other users trading accounts. They can easily fix this by simply reminding their customers that AC:H and PR:L. This gives a CVSS score of 6.8/10 so it's only a medium issue

This morning the trading platform <a href="/NordnetDK/">Nordnet Danmark</a> had an issue where users were getting randomly signed in to other users trading accounts. They can easily fix this by simply reminding their customers that AC:H and PR:L. This gives a CVSS score of 6.8/10 so it's only a medium issue
Lil Endian (@lil_endian) 's Twitter Profile Photo

I just finished a 60 hours fast with just water and black coffee. I’ve never fasted longer than 24 hours before. Good experience and I had a clear mind but my body definitely felt weaker at the end. Next time I think I’ll make some snake juice and see if it makes a difference

Lil Endian (@lil_endian) 's Twitter Profile Photo

Finally back from Google bugSWAT Mexico! What an awesome event! I met so many nice people, had a great time and found a few bugs.

Finally back from Google bugSWAT Mexico! What an awesome event! I met so many nice people, had a great time and found a few bugs.