Sign in

Johan Carlsson

@joaxcar.bsky.social
1K followers 137 following 98 posts

Full time bug bounty hunter. Look for ”joaxcar” on other platforms

PostsRepliesMedia
Reposted by Johan Carlsson
Gareth Heyes @garethheyes.co.uk · 28/08/2025
Imagine you have a XSS vulnerability but you have a undefined variable before your injection. Is all hope lost? Not at all you can use a technique called XSS Hoisting to declare the variable and continue your exploit. Thanks to ycam_asafety for the submission. portswigger.net/web-security...
<script>eval(myUndefVar);var inject="INJECTION_STARTS_HERE";var myUndefVar;alert(1);//";</script>
2187
Johan Carlsson @joaxcar.bsky.social · 07/08/2025
Made a new small challenge where you have to break out of a web worker to leak a token in the URL Only works in Firefox and Safari joaxcar.com/fun/worker/a...
joaxcar.com
Web Worker Test
381
Johan Carlsson @joaxcar.bsky.social · 28/07/2025
Feels like a good time to double down on this
040
Johan Carlsson @joaxcar.bsky.social · 13/07/2025
I often know that I know something. But when having to ask quickly, I stumble. I might have to start generating some "flash card" style questions for myself to try to ingrain some knowledge a bit deeper. This is an example from earlier this week. It's not hard, but how quick and certain are you?
271
Reposted by Johan Carlsson
Julien | MrTuxracer @mrtuxracer.bsky.social · 10/07/2025
I am a huge fan of the #BuyFromEU movement! So far, I've ditched a lot of US stuff already, including Microsoft, Dropbox, 1Password, Notion, Grammarly, Amazon, Slack, and Google. This helped a lot: european-alternatives.eu
european-alternatives.eu
Homepage | European Alternatives
We help you find European alternatives for digital service and products, like cloud services and SaaS products.
3105
Reposted by Johan Carlsson
Geluchat @gelu.chat · 04/07/2025
Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...
gelu.chat
Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter
After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.
3247
Reposted by Johan Carlsson
Jorian @jorianwoltjer.com · 25/05/2025
Double-Clickjacking, or "press buttons on other sites without preconditions". After seeing and experimenting with this technique for a while, I cooked up a variation that combines many small tricks and ends up being quite convincing. Here's a flexible PoC: jorianwoltjer.com/blog/p/hacki...
jorianwoltjer.com
The Ultimate Double-Clickjacking PoC | Jorian Woltjer
Combing a lot of browser tricks to create a realistic Proof of Concept for the Double-Clickjacking attack. Moving a real popunder with your mouse cursor and triggering it right as you're trying to bea...
262
Johan Carlsson @joaxcar.bsky.social · 20/05/2025
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall joaxcar.com/blog/2025/05...
joaxcar.com
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
1186
Johan Carlsson @joaxcar.bsky.social · 18/05/2025
I must have screwed up when setting up bluesky. Added to many “starterpacks”. My feed has been underwhelming. Any one have any idea if there is an active bug bounty community here and how to tap into it?
290
Reposted by Johan Carlsson
Jorian @jorianwoltjer.com · 17/05/2025
The legendary @joaxcar.bsky.social made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below: jorianwoltjer.com/blog/p/hacki...
jorianwoltjer.com
Intigriti May XSS Challenge (0525) | Jorian Woltjer
A challenge by @joaxcar with a small but complex XSS chain, hitting DOM Clobbering with a race condition and abusing a cool URL parsing quirk in JavaScript.
2127
Johan Carlsson @joaxcar.bsky.social · 09/05/2025
I made a small Cross Site Scripting challenge for Intigriti that is live now. Feel free to practice your web hacking skills on it. “Based on a true story” as they say challenge-0525.intigriti.io
challenge-0525.intigriti.io
May Challenge - Intigriti
Find the XSS and WIN Intigriti swag.
190
Reposted by Johan Carlsson
Nicolas Grégoire @agarri.fr · 02/04/2025
Getting feedback like this is what motivates me to work, again and again, on my Burp Suite training course. Thanks @joaxcar.bsky.social ☺️
A screenshot from Johan Carlsson's Linkedin account: "Last week, I participated in Nicolas Gregoire's course "Mastering Burp Suite Pro". I must say it was probably the single best technical course I have taken. Using Burp (one of the main tools I use daily) feels like a whole new experience. I can not recommend enough jumping on one of these sessions."
0204
Reposted by Johan Carlsson
Alex Chapman @ajxchapman.bsky.social · 10/03/2025
Following other's lead, I put together an XSS challenge to solve a somewhat tricky injection I'd come across. In producing the challenge I came up with my solution (so in that way I guess it served it's purpose) but interested in how other's would approach it 🤔 blog.ajxchapman.com/xss/challeng...
1135
Johan Carlsson @joaxcar.bsky.social · 03/02/2025
Finally taking the last steps to "remove" my Twitter account. As I don't want to get impersonated, I will just empty it out and leave it to die slowly. Is there any other way? Must admit my timeline here is not as interesting, but I guess that's up to me to fix.
5201
Reposted by Johan Carlsson
Bug Bounty Reports Explained @gregxsunday.bsky.social · 23/01/2025
Little known trick to bypass CSP feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
081
Reposted by Johan Carlsson
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/01/2025
Three years ago, @joaxcar.bsky.social  was just starting out with bug bounty. Today, he’s GitLab’s TOP1, has bugs on Google and Apple programs, and a reputation as one of the best client-side hackers. Check out our interview🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
0143
Johan Carlsson @joaxcar.bsky.social · 08/01/2025
One of my favorite bugs from last year
0205
Johan Carlsson @joaxcar.bsky.social · 25/12/2024
Another banger pod from BBRE! Really needed this inspiration going into the new year. Never thought about logger++ and elastic, need to test that out
081
Johan Carlsson @joaxcar.bsky.social · 20/12/2024
Here is (finally) the writeup and conclusion of the challenge: joaxcar.com/blog/2024/12... Maybe not the best write-up, but I have to allow myself to actually post, rather than refactor, posts. I hope someone finds it useful. And thanks everyone that participated. Special shoutout to @terjanq.me
joaxcar.com
Sideloading external scripts: a code golf challenge - Johan Carlsson
0114
Johan Carlsson @joaxcar.bsky.social · 18/12/2024
⚠️Challenge time again⚠️ It is based on a real-world situation. Use the HTML injection to leak the flag to an external domain ☃️ This time, send solutions in DM; we don't want to spoil the fun. I also might want to patch any obvious blunder I made creating it joaxcar.com/xss/outer.ht...
2185
Johan Carlsson @joaxcar.bsky.social · 16/12/2024
Was a blast hanging out with @gregxsunday.bsky.social a few hours in gray and cold Gothenburg! Glad that we finally got to meet in real life
060
Johan Carlsson @joaxcar.bsky.social · 12/12/2024
A small code-golf web challenge (free research from you, for me), how short can you make a "fetch content and execute it inline". There is a CSP in a meta tag. Goal: get the content from the file hack.js and have it inserted in the page. like in the image joaxcar.com/xss/self.html
5367
Reposted by Johan Carlsson
Alex Chapman @ajxchapman.bsky.social · 09/12/2024
Dear Bug Bounty programs, You cannot simultaneously prohibit bug escalation and pivoting _and_ insist reports include accurate evidenced risk calculations. Regards, A tired bug hunter
4244
Johan Carlsson @joaxcar.bsky.social · 01/12/2024
Doing some @portswigger.net advent calendar this year as well. Join me on advent.j15.se Its not affiliated with Portswigger but it will link you to one of their chapters each day (random for max excitement) Its created 100% using Cursor so any bugs is AI’s fault
advent.j15.se
PortSwigger Advent Calendar
253
Johan Carlsson @joaxcar.bsky.social · 28/11/2024
An interesting take on the behavior of SAAS companies to put security features in paid plans by @c_r_holm. With an accompanying "name and shame" list raz.sh/blog/2024-11...
raz.sh
Weaponizing SSO for profit - Raz Blog
2120
Johan Carlsson @joaxcar.bsky.social · 26/11/2024
A full patch release without my name in it. Am I loosing my game?! Or is it the newborn messing things up.. need to fix this asap about.gitlab.com/releases/202...
about.gitlab.com
GitLab Patch Release: 17.6.1, 17.5.3, 17.4.5
Learn more about GitLab Patch Release: 17.6.1, 17.5.3, 17.4.5 for GitLab Community Edition (CE) and Enterprise Edition (EE).
190
Johan Carlsson @joaxcar.bsky.social · 26/11/2024
Such a great deepdive into cookies. Read!
082
Johan Carlsson @joaxcar.bsky.social · 22/11/2024
Finally, I took the 5 minutes needed (AI) to "create" the site I always wanted. I won't need to visit random ad-ridden sites just to remember the encoding of characters.. (And I know there are powerful tools and sites to do this. But I want feather light, fast, no bullshit)
6182
Johan Carlsson @joaxcar.bsky.social · 20/11/2024
Trying to sum up my "methodology". Two months ago it led to me reporting three criticals, since then it has only led to "repeat"
160
Johan Carlsson @joaxcar.bsky.social · 19/11/2024
Here is the "writeup". Hope its clear enough, otherwise ask in comments. Note that there are two paths that will result in XSS. And that the "error path" can be reached in numerous different ways, like alternative 1 and 4. Alternative 5 hits the "successful path" and can also be used in many ways
3163
Johan Carlsson @joaxcar.bsky.social · 18/11/2024
Specification challenge! ☃️ Which (if any) of the href values (1-5) would pop an alert in this scenario? 🛑 No testing, just thinking! ⚠️ Warning: answers in comments (bonus: why/why not)
let wrapper = document.createElement("div")
document.body.append(wrapper)
let anchor  = document.createElement("a")

/*1*/ anchor.href = "//<style onload=alert()>"
/*2*/ anchor.href = "<style onload=alert()>"
/*3*/ anchor.href = "https://a.a/<style onload=alert()>"
/*4*/ anchor.href = "https://a.1/<style onload=alert()>"
/*5*/ anchor.href = "a:<style onload=alert()>"

wrapper.innerHTML = anchor.href
8143
Johan Carlsson @joaxcar.bsky.social · 15/11/2024
Read this! Beautiful blog post, and so much to learn from it mizu.re/post/explori...
mizu.re
Exploring the DOMPurify library: Bypasses and Fixes. Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Bypasses and Fixes
0198
Johan Carlsson @joaxcar.bsky.social · 15/11/2024
So the bugs projectdiscovery.io/blog/github-... and projectdiscovery.io/blog/ruby-sa... would they not be mitigated by having "response signing"? which would block adding any extra tags even outside the assertions? Trying to understand SAML, its hard 😅
projectdiscovery.io
GitHub Enterprise SAML Authentication Bypass (CVE-2024-4985 / CVE-2024-9487) — ProjectDiscovery Blog
Introduction In light of the recent Ruby-SAML bypass discovered in GitLab, we set out to examine the SAML implementation within GitHub Enterprise. During our research, we identified a significant vul...
010
Johan Carlsson @joaxcar.bsky.social · 12/11/2024
"'`><h1>asdf</h1> Hello World! excited to test a new procrastination app, the old one broke
0162