Sign in

Tom Anthony

@tomanthony.bsky.social
1.6K followers 48 following 12 posts

Web dev since 1998. Bug bounty & security enthusiast. PhD in AI. CTO at SearchPilot - data driven SEO. www.tomanthony.co.uk

PostsRepliesMedia
Reposted by Tom Anthony
renniepak @renniepak.nl · 24/05/2025
For those who missed it, check out my talk, “Widgets Gone Wild: Exploiting XSS through Flawed postMessage Origin Checks.” 📺 Watch here: www.youtube.com/watch?v=qgB0... 🖥️ Follow along with the slides: 0-a.nl/nahamcon/
youtube.com
Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks
YouTube video by renniepak
1208
Reposted by Tom Anthony
renniepak @renniepak.nl · 24/05/2025
The slides and examples for my talk "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks" at NahamCon can be found here: 0-a.nl/nahamcon/
184
Reposted by Tom Anthony
Johan Carlsson @joaxcar.bsky.social · 20/05/2025
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall joaxcar.com/blog/2025/05...
joaxcar.com
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
1186
Tom Anthony @tomanthony.bsky.social · 19/05/2025
I'm excited to be speaking at #NahamCon2025 on May 23rd! I'm going to be talking about a bug class that I believe is very undervalued, and will outline a methodology for how to find and exploit it in the wild. May the bounties rain down upon you! Details here: www.nahamcon.com
091
Reposted by Tom Anthony
Gareth Heyes @garethheyes.co.uk · 22/11/2024
In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! 🚀 Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Don’t miss it: youtu.be/JERBqoTllaE?...
youtu.be
DEF CON 32 - Splitting the email atom exploiting parsers to bypass access controls - Gareth Heyes
YouTube video by DEFCONConference
29329