alex

2.1K posts

alex banner
alex

alex

@insertScript

@[email protected] # https://t.co/liE6hop4OX Array(10).join('a'-1)+ Batman! #Cure53

Inscrit le Haziran 2012
216 Abonnements6.7K Abonnés
alex retweeté
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
FFFF the axios thing is bad, almost all node.js project use it, we use it. didn't want to install some tool with a bunch of deps just to check if our gcloud/docker images are affected, trivy literally got supply chained two weeks ago lmao built me a small tool. stdlib only, just shells out to docker/gcloud cli. if those are compromised we're all cooked anyway. CHECK YOUR IMAGES. github.com/hacktronai/cull
English
4
11
81
15K
alex
alex@insertScript·
@AmirMSafari Well I learned a lot trying to solve this challenge. But mainly I was reconfirmed that @kinugawamasato is basically living in browsers. Took him 1 hour 11minutes to solve it (assuming he read my message sharing this challenge frame perfect)
English
0
0
3
289
alex
alex@insertScript·
@shhnjk Hm does that work with img and alt text as well 🤔Would be funny especially when you have full control of the remote image
English
1
0
3
262
Jun Kokatsu
Jun Kokatsu@shhnjk·
Pro tip: You can hide an indirect prompt inside markdown link using title. This works in sites like GitHub. `[Text](URL "Title")`
English
1
4
38
3K
alex
alex@insertScript·
Again just a quick JS PoC (nothing new, just some PoC to try it): JS Array length of 4294967295, and push vs [][length]=value behavior. Push fails, assignment works but length value isn't increased anymore. Don't really see how this can be abused. insert-script.com/examples/javas…
English
0
1
7
781
alex retweeté
Nadim Kobeissi
Nadim Kobeissi@kaepora·
Your chance to be part of a historic event for cryptography education in the Levant is still open! The CFP for Cedarcrypt, the most ambitious and exciting cryptography event in the Levant region in recent memory, has a deadline of April 10 and we still have room in the program. If you've been meaning to submit a talk, workshop, or research presentation, now's the time. We want hands-on workshops, lectures on both foundational and real-world topics, and research talks including work in progress. Topics range from post-quantum crypto and ZK proofs to secure implementation and protocol verification. We're also still actively seeking sponsors. Sponsorship funds student stipends directly — it's how we make the event accessible to grad students and early-career researchers worldwide. If your organization is in this space, let's talk. Accepted speakers get travel support, free registration, and accommodation help. July 13–16, Paphos, Cyprus. Join us in making a real difference in how real-world cryptography is taught in the Levant! Come meet and engage with excited new students! cedarcrypt.org
English
0
5
15
2.2K
alex
alex@insertScript·
@rebane2001 The only solutions I can think of: Overwrite the prototypes - Number or Object use document.all as the one exception. Afaik no symbols are utilized sadly for this operator.
English
0
0
0
125
Rebane
Rebane@rebane2001·
js trivia challenge! you can write anything on line one, how are you getting the flag? i originally wanted to make this into a ctf chall, but it's a bit too "win by knowing 1 obscure trick" to be good
Rebane tweet media
English
19
3
229
26.9K
alex
alex@insertScript·
@garethheyes Given how much you always implement in your lunch time - do you eat with one hand and program with the other? :-D
English
1
0
0
184
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
Last night I added GZip and Deflate compression to Hackvertor. I also improved the autodecoder to detect it. Yesterday on my lunch I added autocompletion for HackPad and fixed a bunch of bugs. hackvertor.co.uk/urls/31
English
3
2
23
2.2K
alex
alex@insertScript·
@zhero___ First AmirMSafari publishes an interesting parsing quirk of qs - you are going to (hopefully) publish a report about a new cross-site data exfiltration technique. I like the start of the year .-D
English
1
0
6
864
zhero;
zhero;@zhero___·
spent hours exploring different approaches to improve the exploit and the result is quite promising; report updated I take this opportunity to wish ramadan mubaarak to my fellow believers, enjoy it fully!
zhero;@zhero___

can merely visiting a website lead to cross-site data exfiltration from any site without user interaction? a ""minimal"" PoC has been validated, successfully exfiltrating, as a demonstration, the victim’s gmail address report submitted, hoping to provide more details soon

English
5
9
195
24.8K
alex
alex@insertScript·
@LiveOverflow hahaha thats just awesome xD
English
0
0
1
147
alex retweeté
Justin Gardner
Justin Gardner@Rhynorater·
Chrome auto decodes all url-encoded, non-special characters in the URL for the user. This can be annoying when you're trying to sneak a payload in that looks a little weird. You can bypass this by adding %ff anywhere in the URL.
English
5
38
387
16K
alex retweeté
Nadim Kobeissi
Nadim Kobeissi@kaepora·
Come be part of Cedarcrypt, our historic new initiative to grow cryptography research, development and representation in the Levant region! For too long, the global cryptography community has concentrated its major events in a handful of locations, leaving entire regions underrepresented in the conversations that shape our digital future. Cedarcrypt is here to change that. This July 13-16, 2026, we're bringing together researchers, practitioners, and students at the American University of Beirut - Mediterraneo campus in Paphos, Cyprus, for four days of intensive learning, knowledge sharing, and community building. From secure messaging protocols to post-quantum cryptography, from zero-knowledge proofs to formal verification, Cedarcrypt aims to cover the full spectrum of applied cryptography. Cedarcrypt is about planting a flag and telling the world that real cryptography work can and does emerge from our region. Cedarcrypt aims to create a space where the next generation of cryptographers from the Levant and beyond can learn from established experts, present their own research, and forge connections that will shape their careers. We need you to make this happen. We're seeking workshop leaders to teach hands-on skills, lecturers to share foundational and cutting-edge knowledge, and researchers to present their latest work. Whether you're a seasoned professor or an early-career researcher with fresh ideas, there's a place for you at Cedarcrypt. This is the first edition of what we intend to become an annual tradition. Come be part of our history! Help us build something that will inspire and empower cryptographers for years to come. Our call for proposals is open: submit your workshop or talk, or simply learn more about Cedarcrypt at cedarcrypt.org!
English
1
7
38
13.3K
alex retweeté
zhero;
zhero;@zhero___·
Happy to publish our first research of the year on the SvelteKit framework, downloaded over 800,000 times per week, which led to CVE-2025-67647 (w/@inzo____): Avoiding the paradox: A native full-read SSRF and one‑shot DoS in SvelteKit zhero-web-sec.github.io/research-and-t… Enjoy the read
zhero; tweet media
English
8
61
345
15.9K
alex retweeté
GMO Flatt Security Inc.
GMO Flatt Security Inc.@flatt_sec_en·
We've published a new blog post by RyotaK @ryotkak He discovered 8 methods to bypass safety mechanisms in Claude Code, leading to arbitrary command execution. We recommend updating to v1.0.93 or later to fix this vulnerability (CVE-2025-66032). flatt.tech/research/posts…
English
3
83
239
62.7K
alex
alex@insertScript·
@nitzukai Maybe the G502 X LIGHTSPEED? The G502 series still has some unecessary buttons (at least you can remove the big one at the left side) but I never press them accidentally^^
English
0
0
0
39
nitzu 🫧
nitzu 🫧@nitzukai·
how does this have 1k comments
English
12
0
71
44.9K
nitzu 🫧
nitzu 🫧@nitzukai·
why is the mouse industry so fucked up? why can't I find a mouse that: - does not look like a RGB gaming rig - doesn't have a ton of buttons on it - is wireless - has a good build quality which doesn't have a scroll wheel that dies within 2 months - is not MX Master
English
1.6K
166
10.9K
758.7K