The Cherabog

31 posts

The Cherabog banner
The Cherabog

The Cherabog

@MrCherna

Vibing with hacking, music, and gaming—plus the occasional chess match to keep things sharp.

Katılım Mart 2024
95 Takip Edilen127 Takipçiler
AmirMohammad Safari
AmirMohammad Safari@AmirMSafari·
Nicely crafted payload for the onbeforematch event handler with @nowaskyjr. I used it to build a payload that bypasses Cloudflare WAF. The interesting part? If you remove }_, the payload stops working :D
AmirMohammad Safari tweet media
Nowasky@nowaskyjr

Combining two techniques I recently showed: attribute merging of <html>/<body> tags and using hidden=until-found to trigger onbeforematch via fragment navigation in Firefox. #xss" target="_blank" rel="nofollow noopener">storage.googleapis.com/nowaskyjr/poc_… #xss

English
7
9
118
8.3K
YS
YS@YShahinzadeh·
I haven’t fully returned to BB since my H1 acc was suddenly closed, but this week I tried to start working again. I spent some time on BC and found an XSS and an IDOR, the XSS was easy with a simple payload :]
YS tweet media
English
39
3
381
12.2K
Josefcfc
Josefcfc@yousefccfc·
1-click ATO via a postMessage flaw This is my 2nd ever finding and I’m really happy about it! The severity could be high, but I’m not letting that overshadow the joy of this bounty 😄 Huge thanks to @voorivex for teaching us this trick 🙌
Josefcfc tweet media
English
25
5
231
9.1K
𝙠𝙖𝙢𝙞𝙠𝙖𝙯𝙚
Last day I found an XSS that couldn’t be detected with Nuclei, Httpx, X8, ... cause of aggressive connection handling, even with all options, servers just didn’t respond. So I wrote a lightweight Go tool to reliably test GET/POST parameter reflections. github.com/xkmikze/kzxss/
English
12
28
201
11.6K
Shade
Shade@he_shades·
@Nimublla @voorivex مهم اینه که باگی زدی که سایت رنده شد برو کارت درسته حاج ایلیا
فارسی
1
0
1
192
Amir
Amir@Amir67760784·
@Nimublla @voorivex ای ول ایشالا بعدی تریاژه🔥🔥
فارسی
1
0
2
138
Abolfazl
Abolfazl@Abolfazlda2pac·
@Nimublla @voorivex مشالله داش ایلیا بنازم ادامه بده ❤️❤️❤️
فارسی
1
0
4
239