AbolFazl (@mptslk) 's Twitter Profile
AbolFazl

@mptslk

ID: 1522586643252797440

calendar_today06-05-2022 14:38:51

34 Tweet

131 Followers

612 Following

Bytebytego (@bytebytego) 's Twitter Profile Photo

Session, Cookie, JWT, Token, SSO, and OAuth 2.0 Explained in One Diagram When you login to a website, your identity needs to be managed. Here is how different solutions work: - Session - The server stores your identity and gives the browser a session ID cookie. This allows

Session, Cookie, JWT, Token, SSO, and OAuth 2.0 Explained in One Diagram 
 
When you login to a website, your identity needs to be managed. Here is how different solutions work: 
 
- Session - The server stores your identity and gives the browser a session ID cookie. This allows
Meydi (@neotrony) 's Twitter Profile Photo

Explore my blog on XSS WAF bypass, covering various tricks and techniques: meydi.hashnode.dev/master-of-xss-… #bugbounty #bugbountytip #xss

Xin (@zxc29r) 's Twitter Profile Photo

فکت : کنار باگ بانتی باید تراپی هم بری وگرنه چیز جز یه آدم عصبی ازت نمی‌مونه

Meydi (@neotrony) 's Twitter Profile Photo

Just found an interesting behavior in Firefox that can be used for XSS: If a response lacks the Content-Type header, Firefox renders it as text/plain. But if the URL ends with an extension like .html, Firefox treats it as that. #bugbounty #bugbountytips

Just found an interesting behavior in Firefox that can be used for XSS:
If a response lacks the Content-Type header, Firefox renders it as text/plain.
But if the URL ends with an extension like .html, Firefox treats it as that.
#bugbounty #bugbountytips
Meydi (@neotrony) 's Twitter Profile Photo

A tiny blog post of mine about exploiting self-XSS using disk cache— inspired by Jorian Hope you like it! mey-d.github.io/posts/self-xss…

AbolFazl (@mptslk) 's Twitter Profile Photo

Quick Tip: Hunting CORS? Go beyond payloads. In DevTools → debugger, search for regex / RegExp and grab any domains you see. Test them as Origins — broken regex on trusted domains can = bypass 🚨 And don’t forget: some may be purchasable 👀 #bugbountytip #bugbountytips

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below: portswigger.net/research/inlin…

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes! Learn how below:

portswigger.net/research/inlin…