Tarik
@tw4vesx
ID: 1430204350152986632
24-08-2021 16:24:49
46 Tweet
45 Followers
339 Following
While playing a challenge by Salvatore Abello, I found a pretty interesting way to exploit Dangling Markup with a strict CSP. All you need is an <iframe>, <object> or <embed> set to about:blank, with a dangling name= attribute. This vulnerable page should be iframable.
Last week our CISO asked me to present on āzero trust architecture.ā I donāt know what that means. I make $340,000 a year. I havenāt touched a firewall since Obamaās first term. But I have a CISSP. I passed by memorizing acronyms. I still donāt know what half of them stand for. I