Kévin Gervot (Mizu) @mizu.re · 07/09/2026A logical bug that I've reported to MariaDB has just been disclosed! 🎉 It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D You can find more details 👇 hackerone.com/reports/3876... 195
Kévin Gervot (Mizu) @mizu.re · 17/08/2026Recently, I've been looking at DOMPurify again, trying to find ways to bypass 3.x.x after browsers started encoding attrs during serialization. I ended up with a nice ≤3.2.6 Safari default-configuration bypass using only SMIL tags/attrs :D Details 👇 mizu.re/post/dompuri... 042
Reposted by Kévin Gervot (Mizu)CaidoIO @caido.io · 27/04/2026🚀New plugin in the Caido Store! Introducing "DOMLogger++" by @mizu.re Track DOM-based flows to see how user input reaches sensitive browser APIs, with data captured by the browser extension. Check out more details: github.com/kevin-mizu/d... 022
Kévin Gervot (Mizu) @mizu.re · 12/04/2026The #FCSC2026 ended today, and my write-ups are now available here: mizu.re/post/fcsc-20... 🚩 I'm really happy with the challenges I managed to create this year! It would be too long to list everything, so here's a little teaser below 👇 1/2 110
Kévin Gervot (Mizu) @mizu.re · 08/04/2026I'm happy to release the first version of my DOMLogger++ plugin for @caido.io! 🔎 It improves the browser extension in several ways: • Persistent, per-project storage • Temporary session recording • AI support • Stack trace reconstitution • ... 👉 github.com/kevin-mizu/d... 031
Kévin Gervot (Mizu) @mizu.re · 24/10/2025A quick update has been made to DOMLogger++ to add / update a few things. It's not a big deal, but it should allow interesting stuff to be done :) It should be available on the stores in the coming hours. 000
Reposted by Kévin Gervot (Mizu)Jorian @jorianwoltjer.com · 19/09/2025My first post for the @ctbbpodcast.bsky.social Research Lab is live. Super excited to be part of this team, can't wait to see what crazy research is gonna come from this! lab.ctbb.show/research/Exp...lab.ctbb.showExploiting Web Worker XSS with BlobsWays to turn XSS in a Web Worker into full XSS, covering known tricks and a new generic exploit using Blob URLs with the Drag and Drop API 093
Kévin Gervot (Mizu) @mizu.re · 08/09/2025For the @ASIS_CTF, I created a challenge based on an interesting (novel?) DOM Clobbering technique! 🚩 In short, in non-strict mode, HTMLCollection items are not writable. This blocks property assignment, allowing unexpected values to be created 😄 👉 mizu.re/post/under-t... 040
Reposted by Kévin Gervot (Mizu)d4d @zakfedotkin.bsky.social · 03/09/2025We've just published a novel technique to bypass the __Host and __Secure cookie flags, to achieve maximum impact for your cookie injection findings: portswigger.net/research/coo...portswigger.netCookie Chaos: How to bypass __Host and __Secure cookie prefixesBrowsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve 11214
Kévin Gervot (Mizu) @mizu.re · 03/09/2025DOMLogger++ v1.0.9 is now out and available! 🎉 This update fixes a lot of issues, including the historical DevTools bug on Chromium 🔥 It also brings full Caido session handling, which is going to be useful in the near future! 👀 👉 github.com/kevin-mizu/d... 1/2 120
Kévin Gervot (Mizu) @mizu.re · 25/08/2025I've released a DOMLogger++ config that helps detect any replacements occurring in a DOMPurify output by inserting and tracking a canary value at runtime. I think it highlights how useful DOMLogger++ can be for tracking JS execution :D 👉 github.com/kevin-mizu/d... 1/3 130
Reposted by Kévin Gervot (Mizu)James Kettle @jameskettle.com · 07/08/2025The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.comhttp1mustdie.comHTTP/1.1 Must DieUpstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now 04022
Kévin Gervot (Mizu) @mizu.re · 24/07/2025I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4 12313
Reposted by Kévin Gervot (Mizu)Geluchat @gelu.chat · 04/07/2025Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...gelu.chatFinding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time HunterAfter seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey. 3247
Kévin Gervot (Mizu) @mizu.re · 22/05/2025I've released my CTF bot template! :D It's not a big deal, but it comes with a heavily hardened Docker setup. The bot also sends a lot of debugging information over the TCP socket (console logs, navigation), which makes remote debugging much easier! 🔎 👉 github.com/kevin-mizu/b... 052
Reposted by Kévin Gervot (Mizu)Johan Carlsson @joaxcar.bsky.social · 20/05/2025Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall joaxcar.com/blog/2025/05...joaxcar.comConfetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson 1186
Reposted by Kévin Gervot (Mizu)James Kettle @jameskettle.com · 14/05/2025I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓ 23918
Reposted by Kévin Gervot (Mizu)d4d @zakfedotkin.bsky.social · 30/04/2025Think you’ve seen every OS command injection trick? Think again, read our latest blog post! Link in the comments👇 1279
Kévin Gervot (Mizu) @mizu.re · 28/04/2025The #FCSC2025 ended yesterday, and my write-ups are now available here 👇 mizu.re/post/fcsc-2025… Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩 1/2 262
Reposted by Kévin Gervot (Mizu)Gareth Heyes @garethheyes.co.uk · 25/04/2025Firefox treats multipart/x-mixed-replace like HTML. Chrome doesn’t. That tiny difference? It can turn a "non-exploitable" XSS into a real one. Abuse boundary handling, bypass filters, and make your payload land. thespanner.co.uk/making-the-u...thespanner.co.ukMaking the Unexploitable Exploitable with X-Mixed-Replace on Firefox - The SpannerIn this post, we’ll look at an interesting difference in how Firefox and Chrome handle the multipart/x-mixed-replace content type. While Chrome treats it as an image, Firefox renders it as HTML - some... 0188
Kévin Gervot (Mizu) @mizu.re · 18/04/2025This year again, with @bi.tk, we've made the Web challenges 🚩 The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁 Btw, even if you're not doing Web challenges, there are 100+ challenges in various categories, you should find something you like! 1144
Reposted by Kévin Gervot (Mizu)Gareth Heyes @garethheyes.co.uk · 20/03/2025🔥 My Black Hat talk is now live! 🎥 Watch how email parsing quirks turned into RCE in Joomla and critical access control bypasses across major platforms. See how these subtle flaws led to serious exploits! www.youtube.com/watch?v=Uky4...youtube.comSplitting the Email Atom: Exploiting Parsers to Bypass Access ControlsYouTube video by Black Hat 0236
Reposted by Kévin Gervot (Mizu)Gareth Heyes @garethheyes.co.uk · 18/03/2025You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study. portswigger.net/research/sam...portswigger.netSAML roulette: the hacker always winsIntroduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library 05323
Kévin Gervot (Mizu) @mizu.re · 02/03/2025For this challenge, it was necessary to abuse a discrepancy between the DOM and the rendered page in Firefox's cache handling 💽 👉 bugzilla.mozilla.org/show_bug.cgi... This allows to shift iframe rendering from one to another leading to a sandbox bypass 🔥 👉 mizu.re/post/an-18-y... 091
Kévin Gervot (Mizu) @mizu.re · 28/02/2025With @gelu.chat, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! 🚀 If you have some time this weekend, give it a try! 👀 👉 pwnme.phreaks.fr 0144
Kévin Gervot (Mizu) @mizu.re · 27/02/2025DOMLogger++ v1.0.8 is now out and available! 🎉 This update includes several UX improvements, such as syntax highlighting and new shortcuts. Major changes have been made to custom types and several annoying bugs have been fixed 🚀 👉 github.com/kevin-mizu/d... 081
Kévin Gervot (Mizu) @mizu.re · 10/02/2025The solution to this challenge is available here: mizu.re/post/explori... :) 040
Kévin Gervot (Mizu) @mizu.re · 10/02/2025I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)! Link 👇 mizu.re/post/explori... 1/2 22711
Kévin Gervot (Mizu) @mizu.re · 07/02/2025Thanks to the recent @portswiggerres.bsky.social top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify security! 😁 Before releasing it, I would like to share a small challenge 🚩 Challenge link 👇 challenges.mizu.re/xss_04.html 1/2 1176
Reposted by Kévin Gervot (Mizu)PortSwigger Research @portswiggerres.bsky.social · 04/02/2025The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...portswigger.netTop 10 web hacking techniques of 2024Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year 26636
Reposted by Kévin Gervot (Mizu)Gareth Heyes @garethheyes.co.uk · 28/01/2025Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique. portswigger.net/research/byp... 03822
Kévin Gervot (Mizu) @mizu.re · 16/01/2025Looks like my DOMPurify article has been nominated! I know I haven't released part 2 yet, but if you enjoyed it, I would really appreciate if you could vote for it! 🫶 mizu.re/post/explori... 093
Reposted by Kévin Gervot (Mizu)James Kettle @jameskettle.com · 08/01/2025Nominations are now open for the Top 10 Web Hacking Techniques of 2024! Browse the contestants and submit your own here: portswigger.net/research/top...portswigger.netTop ten web hacking techniques of 2024: nominations openNominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an 12819
Reposted by Kévin Gervot (Mizu)BitK @handle.invalid · 20/12/2024I've pushed some updates to Dom-Explorer: - Allow multiple pipeline embed - Short links for sharing/sync - Support for DomPurify triggers - User settings Give it a try and share your findings! yeswehack.github.io/Dom-Exploreryeswehack.github.ioDom-Explorer 2206
Reposted by Kévin Gervot (Mizu)terjanq @terjanq.me · 14/12/2024Got sniped into the challenge and ended up doing some cool XSS research :D 11 char XSS with mind-boggling race-conditions. TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char) It's shorter than location=name !! terjanq.me/solutions/jo...terjanq.me11 char XSS (slow race-condition) 13011
Reposted by Kévin Gervot (Mizu)Luke Jahnke @nastystereo.com · 10/12/2024My latest blog post is live! Check your Ruby on Rails applications for the use of params[:_json] nastystereo.com/security/rai... 13314
Reposted by Kévin Gervot (Mizu)RyotaK @ryotak.net · 07/12/2024If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos... For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)flatt.techCompromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command InjectionIntroduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac... 0178
Reposted by Kévin Gervot (Mizu)PortSwigger Research @portswiggerres.bsky.social · 04/12/2024Did you know you can use an ancient magic cookie to downgrade parsers and bypass WAFs?! Hope you enjoy this quality bit of RFC-diving from @d4d89704243.bsky.social! portswigger.net/research/byp...portswigger.netBypassing WAFs with the phantom $Version cookieHTTP cookies often control critical website features, but their long and convoluted history exposes them to parser discrepancy vulnerabilities. In this post, I'll explore some dangerous, lesser-known 17327
Reposted by Kévin Gervot (Mizu)Luke Jahnke @nastystereo.com · 04/12/2024My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation! nastystereo.com/security/rub... 1198
Reposted by Kévin Gervot (Mizu)Jorian @jorianwoltjer.com · 27/11/2024To summarize what I have learned about Mutation XSS, my CVE, and the solution to my challenge, I wrote a post going through it all. If you like regular XSS, this is a whole new world of crazy techniques and many sanitizer bypasses. You too can learn this! jorianwoltjer.com/blog/p/hacki...jorianwoltjer.comPost: Mutation XSS: Explained, CVE and Challenge | Jorian WoltjerLearn how to bypass HTML sanitizers by abusing the intricate parsing rules and mutations. Including my CVE-2024-52595 (lxml_html_clean bypass) and the solution to a hard challenge I shared online 0239
Reposted by Kévin Gervot (Mizu)April King @april.social · 21/11/2024Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h... 1216853
Reposted by Kévin Gervot (Mizu)Luke Jahnke @nastystereo.com · 27/11/2024My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon 37829