Taher Barodawala
@tahersb
Security engineer and always a student | Geek | Product Security @ VMware | Mostly RTs
infosec(dot)exchange/@tahersb
ID: 85590189
https://awesomesec.com/ 27-10-2009 15:18:28
763 Tweet
96 Followers
920 Following
ICYMI @[email protected] explained a few DOMPurify bypasses yesterday (youtu.be/QBkLI35sxVs). Today we're publishing a first part of two-part series about how he helped secure DOMPurify: research.securitum.com/helping-secure…
Having discovered various issues with Windows mini-filter drivers lately I found public information about how to analyze such drivers for security issues somewhat lacking. Therefore today I've put out a blog post to try and fix that glitch :-) googleprojectzero.blogspot.com/2021/01/huntin…
Inspired by Gareth Heyes \u2028' CSP bypass in PayPal, for the first time in 4 years, I found again that JS resources added by CloudFlare could introduce a CSP bypass. l0.cm/cf_cspbypass.h…
⚠️📱Android Pentest Resources 👇 👉 Android app pentesting Hacktricks by @carlospolopm book.hacktricks.xyz/mobile-apps-pe… 👉 android pentest mindmap xmind.net/m/DVAq9V/# 👉 Android pentest checklist by Harsh Bothra xmind.net/m/GkgaYH/#