Matan Berson (@mtnber) 's Twitter Profile
Matan Berson

@mtnber

Hacker and bug bounty hunter mostly focusing on client-side security. h1-702 Vigilante, h1-65 Eliminator, AWC23 Best New Hacker

ID: 1262701908587884544

linkhttp://matanber.com calendar_today19-05-2020 11:09:46

235 Tweet

3,3K Followers

252 Following

Matan Berson (@mtnber) 's Twitter Profile Photo

This was a good one, I’m proud of it. We managed to get very technical and even drop a new technique while not requiring too much prior knowledge Thanks to Critical Thinking - Bug Bounty Podcast for having me again

Matan Berson (@mtnber) 's Twitter Profile Photo

Here's a code snippet that as far as I can tell pretty much solves prototype pollution. It's based on github.com/tc39/proposal-…, and after running it you can access an object's prototype with object[Symbol.instanceProto], and object["__proto__"] will be undefined.

Here's a code snippet that as far as I can tell pretty much solves prototype pollution. It's based on github.com/tc39/proposal-…, and after running it you can access an object's prototype with object[Symbol.instanceProto], and object["__proto__"] will be undefined.
Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜 The research article is available here: mizu.re/post/exploring… The slides are available here: slides.com/kevin-mizu/gre… 1/3

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜

The research article is available here: mizu.re/post/exploring…
The slides are available here: slides.com/kevin-mizu/gre…

1/3
Critical Thinking - Bug Bounty Podcast (@ctbbpodcast) 's Twitter Profile Photo

We made it, y'all! 100 Episodes. We put together a banger for y'all to celebrate: 8 crazy bugs from top hackers giveaways sad announcement from Joel Margolis (teknogeek) Shift - Caido AI announcement It has been a great ride - cheers to many more episodes! youtu.be/ANYtLQrT-F0

Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

Our talk at #BHEU is done! Hope you all enjoyed it. 😉 A detailed blog is on the way, but in the meantime, check out the pre-alpha website worst.fit for early access and the slides! Huge thanks to Black Hat and my awesome co-presenter splitline 👁️🐈‍⬛! 🐈‍

Matan Berson (@mtnber) 's Twitter Profile Photo

I’m very excited to be part of the team! I can’t wait to collaborate with all of these amazing hackers and learn from them

I’m very excited to be part of the team! I can’t wait to collaborate with all of these amazing hackers and learn from them
slonser (@slonser_) 's Twitter Profile Photo

In 2024, I interacted a lot with Extensions. I decided to create a resource that will help with a basic understanding of extensions and key attacks. P.S. I tried to make everything as clear as possible and hope it won’t feel too overwhelming anywhere. extensions.neplox.security

Sam Curry (@samwcyo) 's Twitter Profile Photo

New blog post with shubs: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: samcurry.net/hacking-subaru

Gal Weizman (@weizmangal) 's Twitter Profile Photo

Got back last week from Tokyo🇯🇵 where I caught Renée Boudreault & @Slonser's talk with kumavis Being part of the web/browser/JavaScript security niche from the perspective of crypto wallets specifically, felt like a talk to not miss Here's what I learned 🧵 x.com/neploxaudit/st…

Got back last week from Tokyo🇯🇵 where I caught <a href="/renbou/">Renée Boudreault</a> &amp; @Slonser's talk with <a href="/kumavis_/">kumavis</a>

Being part of the web/browser/JavaScript security niche from the perspective of crypto wallets specifically, felt like a talk to not miss

Here's what I learned 🧵

x.com/neploxaudit/st…
Jorian (@j0r1an) 's Twitter Profile Photo

The legendary Johan Carlsson made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below: jorianwoltjer.com/blog/p/hacking…

Matan Berson (@mtnber) 's Twitter Profile Photo

I’m in a pwnfunction video! Check it out, it’s very well made and the vulnerability chain is quite unique youtube.com/watch?v=RLyhPG…