Roman Shafigullin (@shafigullin) 's Twitter Profile
Roman Shafigullin

@shafigullin

Security at LinkedIn

ID: 35439611

linkhttps://lnkd.in/xss calendar_today26-04-2009 09:59:30

2,2K Tweet

5,5K Followers

912 Following

Хабр (@habr_com) 's Twitter Profile Photo

Красная команда, чёрный день: почему матерые пентестеры лажают в Red Team Даже опытные специалисты не всегда видят тонкие различия между пентестами и Red Team. Разница кроется в подходе к выявлению уязвимостей и оценке безопасности организации: u.habr.com/MGSnU

Красная команда, чёрный день: почему матерые пентестеры лажают в Red Team

Даже опытные специалисты не всегда видят тонкие различия между пентестами и Red Team. Разница кроется в подходе к выявлению уязвимостей и оценке безопасности организации: u.habr.com/MGSnU
Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

ooh, this works on Chrome Canary :D <input type="hidden" oncontentvisibilityautostatechange="alert(/ChromeCanary/)" style="content-visibility:auto">

Lukas Weichselbaum (@we1x) 's Twitter Profile Photo

The dedication and hard work has payed off: "for hundreds of complex web applications that are built on Google’s hardened and safe-by-design frameworks, we've averaged less than one XSS report per year in total" (see page 9 of the whitepaper).

MDN Web Docs (@mozdevnet) 's Twitter Profile Photo

Did you know about Strict Mode? 🤔 ✨ "use strict"; ✨ Strict Mode catches silent errors, making your code more predictable and easier to debug. It also improves performance and helps you write more secure JavaScript code. See how 👇 developer.mozilla.org/en-US/docs/Web…

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜 The research article is available here: mizu.re/post/exploring… The slides are available here: slides.com/kevin-mizu/gre… 1/3

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜

The research article is available here: mizu.re/post/exploring…
The slides are available here: slides.com/kevin-mizu/gre…

1/3
James Kettle (@albinowax) 's Twitter Profile Photo

We’re finally live! You can now watch “Listen to the whispers: web timing attacks that actually work” on YouTube: youtube.com/watch?v=zOPjz-…

Alisa Esage Шевченко (@alisaesage) 's Twitter Profile Photo

Releasing full 2+hr video of my browser exploitation workshop from VXCON 2024: youtube.com/live/b9OhamkAY… In which I show what goes inside the mind of a skilled hacker while exploiting a highly non-trivial vulnerability in v8, from zero to exploit concept. Especially this workflow

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

Developers, tired of DOM XSS in your web applications? 😩 We were too. See how we refactored our code to solve Trusted Types violations in Gmail & AppSheet. Your guide to a safer web is here! bughunters.google.com/blog/585078655…