Hack Liberty
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@c0mmandoMA to Netsec • 8 months ago

Stealing passwords from infosec Mastodon - without bypassing CSP

portswigger.net

external-link
message-square
0
1
external-link

Stealing passwords from infosec Mastodon - without bypassing CSP

portswigger.net

@c0mmandoMA to Netsec • 8 months ago
message-square
0
The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose

cross-posted from: https://community.hackliberty.org/post/9544

The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP.

alert-triangle
You must log in or register to comment.

Netsec

!netsec
Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !netsec@links.hackliberty.org

netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers everywhere. ‎

Rules

  1. Don’t do unto others what you don’t want done unto you.
  2. No Porn, Gore, or NSFW content. Instant Ban.
  3. No Spamming, Trolling or Unsolicited Ads. Instant Ban.
  4. Stay on topic in a community. Please reach out to an admin to create a new community.
  • 1 user / day
  • 3 users / week
  • 13 users / month
  • 42 users / 6 months
  • 384 subscribers
  • 125 Posts
  • 48 Comments
  • Modlog
  • mods:
  • @c0mmando
  • BE: 0.18.4
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org