Sign in

terjanq

@terjanq.me
2.6K followers 150 following 37 posts

security enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish. infosec at @google. opinions are mine. From: twitter.com/terjanq

PostsRepliesMedia
Reposted by terjanq
Jorian @jorianwoltjer.com · 26/01/2025
During #x3ctf, I discovered an unintended solution that turned out to be a pretty cool generic technique. It allows you to detect the result of a selector during CSS Injection, bypassing any CSP restricting external requests! Check out the writeup below: jorianwoltjer.com/blog/p/ctf/x...
jorianwoltjer.com
Post: x3CTF - blogdog (+ new CSS Injection XS-Leak!) | Jorian Woltjer
A "hard web xssbot" challenge about a fun browser quirk with the is= attribute to perform CSS Injection. Bypass the strict CSP with an unintended new technique to XS-Leak a selector's result by detect...
2247
Reposted by terjanq
Johan Carlsson @joaxcar.bsky.social · 20/12/2024
Here is (finally) the writeup and conclusion of the challenge: joaxcar.com/blog/2024/12... Maybe not the best write-up, but I have to allow myself to actually post, rather than refactor, posts. I hope someone finds it useful. And thanks everyone that participated. Special shoutout to @terjanq.me
joaxcar.com
Sideloading external scripts: a code golf challenge - Johan Carlsson
0114
terjanq @terjanq.me · 15/12/2024
settings ➡️ content & media ➡️ threads ➡️ experimental Helps a lot with longer threads!
061
Reposted by terjanq
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social · 14/12/2024
Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earned a $5,000 bounty for it. Here's the story and a beginner-friendly deep dive into V8 exploit development. watch: youtu.be/R3SE4VKj678?...
youtu.be
Hacking Discord for $5000 Bounty
YouTube video by Mrgavyadha
1188
terjanq @terjanq.me · 14/12/2024
Got sniped into the challenge and ended up doing some cool XSS research :D 11 char XSS with mind-boggling race-conditions. TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char) It's shorter than location=name !! terjanq.me/solutions/jo...
terjanq.me
11 char XSS (slow race-condition)
13011
Reposted by terjanq
terjanq @terjanq.me · 13/12/2024
15 terjanq.me/solutions/jo... Can be most likely improved but didn't yet figure out how to properly race condition with shorter payloads like top.x.x+="" 😶
terjanq.me
151
terjanq @terjanq.me · 10/12/2024
Extended the starter with shy writers! 😀 If you're not on the list but write about web security, then feel free to reply with the article you're most proud of, and I will add you to the pack! Make sure to resubscribe to not not miss on the amazing 🌐research! go.bsky.app/9JXnB17
92910
Reposted by terjanq
terjanq @terjanq.me · 01/12/2024
I started a Web Security Writers starter pack. Had to add 7 accounts so settled on a couple of obvious names but the idea I have for the starter is different. Please share your BEST writeup / article in the reply and I will add you to the pack! Let's shake the platform a bit with amazing research! 🕸️
go.bsky.app
Web Security Writers
Join the conversation
15378
terjanq @terjanq.me · 01/12/2024
I started a Web Security Writers starter pack. Had to add 7 accounts so settled on a couple of obvious names but the idea I have for the starter is different. Please share your BEST writeup / article in the reply and I will add you to the pack! Let's shake the platform a bit with amazing research! 🕸️
go.bsky.app
Web Security Writers
Join the conversation
15378
Reposted by terjanq
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
terjanq @terjanq.me · 27/11/2024
Great article about mXSS by @jorianwoltjer.com!
0110
Reposted by terjanq
Freddy @freddyb.bsky.social · 27/11/2024
Modern solutions against cross-site attacks (frederikbraun.de/modern-solut...): An article about cross-site leak attacks and browser-based defenses. You will also learn why web security best practices is always opt-in and finally how YOU can get increased security controls.
frederikbraun.de
Modern solutions against cross-site attacks
Modern solutions against cross-site attacks
03419
Reposted by terjanq
James Kettle @jameskettle.com · 21/11/2024
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX
459530
Reposted by terjanq
April King @april.social · 21/11/2024
Handling Cookies is a Minefield: Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out. grayduck.mn/2024/11/21/h...
facebook errornetflix errorokta errorwhatsapp error
1216853
terjanq @terjanq.me · 20/11/2024
Just crossed 10% of my twitter audience. 90% more to go! 🚀
3200
terjanq @terjanq.me · 19/11/2024
Great article about multipart parsing. Reminds me about the bypasses I found in modsec parser medium.com/@terjanq/waf...
medium.com
WAF bypasses via 0days
based on findings from a live hacking event
1237
Reposted by terjanq
Michele Spagnuolo @miki.it · 17/11/2024
Happy to publish the effort of my last five years: Security Signals. research.google/pubs/securit...
research.google
Security Signals: Making Web Security Posture Measurable At Scale
0277
Reposted by terjanq
Lukas Weichselbaum @webappsec.dev · 17/11/2024
I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here 🙂 go.bsky.app/Uf8dZhz
165525
Reposted by terjanq
Lukas Weichselbaum @webappsec.dev · 16/11/2024
If you're into web security take a look at my LocoMocoSec keynote slides from this summer about "Google's Recipe for Scaling (Web) Security": speakerdeck.com/lweichselbau...
1218
terjanq @terjanq.me · 13/11/2023
Bring back the bird!
060