Jun Kokatsu (@shhnjk) 's Twitter Profile
Jun Kokatsu

@shhnjk

Hacking the Web and Browsers. Opinions are my own.
infosec.exchange/@shhnjk

ID: 1279334534

linkhttps://shhnjk.blogspot.com/ calendar_today19-03-2013 02:28:45

1,1K Tweet

5,5K Followers

127 Following

Jun Kokatsu (@shhnjk) 's Twitter Profile Photo

Did anyone find a real world XSS using sonarsource.com/blog/encoding-… ? I'm wondering how many sites still does not set charset.

Google VRP (Google Bug Hunters) (@googlevrp) 's Twitter Profile Photo

❌ Eliminating almost all exploitable web vulnerabilities? This blog post covers how the Google security team implemented a high-assurance web framework to achieve this goal for its services, and what this framework's most important characteristics are. bughunters.google.com/blog/664431627…

Jun Kokatsu (@shhnjk) 's Twitter Profile Photo

If you are interested in AI Security, come work with me, Sal ꙮ, and many other amazing engineers in Agent Security team! We have open roles for security engineers and software engineers 🙂 google.com/about/careers/… google.com/about/careers/… google.com/about/careers/…

@securitymb@infosec.exchange (@securitymb) 's Twitter Profile Photo

🔥 A new (more difficult) era for mXSS will come soon! If nothing breaks, Chromium will start escaping "<" and ">" in attributes starting with M138. See chromestatus.com/feature/626498… for details.

Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

lol, this works on Firefox: <object data=# codebase=javascript:alert(document.domain)//> OR <embed src=# codebase=javascript:alert(document.domain)//>

Jun Kokatsu (@shhnjk) 's Twitter Profile Photo

「よくわかんないけど… なんもわからん!」をモットーに、Shibuya.XSSでXSSと全く関係ない話をします!

Jun Kokatsu (@shhnjk) 's Twitter Profile Photo

#shibuyaxss 楽しかった! 会場を貸して頂いたサイボウズ様、いつも有難う御座います! そして忙しい中開催してくれたYosuke HASEGAWAさんにも感謝。 スライドは来週には公開できると思うので、フォローしてお待ち下さいw