
Matan Berson
@mtnber
Hacker and bug bounty hunter mostly focusing on client-side security. h1-702 Vigilante, h1-65 Eliminator, AWC23 Best New Hacker
ID: 1262701908587884544
http://matanber.com 19-05-2020 11:09:46
235 Tweet
3,3K Followers
252 Following

Great trick by Kévin GERVOT (Mizu)! I always thought caches were scoped to the current JS context, but apparently they’re scoped to the entire origin

This was a good one, I’m proud of it. We managed to get very technical and even drop a new technique while not requiring too much prior knowledge Thanks to Critical Thinking - Bug Bounty Podcast for having me again



We made it, y'all! 100 Episodes. We put together a banger for y'all to celebrate: 8 crazy bugs from top hackers giveaways sad announcement from Joel Margolis (teknogeek) Shift - Caido AI announcement It has been a great ride - cheers to many more episodes! youtu.be/ANYtLQrT-F0









The legendary Johan Carlsson made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below: jorianwoltjer.com/blog/p/hacking…

New video! XSS like you’ve never seen before youtube.com/watch?v=RLyhPG… Huge thanks to Matan Berson

