Stealing Financial Data on Logout: A DOM XSS Story
A logout redirect validated the hostname and ignored the scheme. One encoded newline turned it into same-origin DOM XSS that waited for login and read loan and bank data.
A logout redirect validated the hostname and ignored the scheme. One encoded newline turned it into same-origin DOM XSS that waited for login and read loan and bank data.
How an encoded slash bypassed VS Code’s Webview resource allowlist and turned a sandboxed view into an arbitrary file reader.
How misplaced rate limits let one validator freeze a blockchain with 320 valid blocks and no transaction fees.
I tried to hide code in a picture. A few dead-ends later, one ordinary HTTPS link ran my JavaScript inside any user’s logged-in app. No password, one tap.