Matan Berson

253 posts

Matan Berson banner
Matan Berson

Matan Berson

@MtnBer

Hacker and bug bounty hunter mostly focusing on client-side security. h1-702 Vigilante, h1-65 Eliminator, AWC23 Best New Hacker

Katılım Mayıs 2020
267 Takip Edilen4K Takipçiler
Sabitlenmiş Tweet
Matan Berson
Matan Berson@MtnBer·
Just released my blog post "Bidding Like a Billionaire - Stealing NFTs With 4-Char CSTIs"! It's about a very impactful and technically interesting client-side bug I found in a major NFT site. matanber.com/blog/4-char-cs…
English
17
68
393
39.8K
Matan Berson retweetledi
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
In a shameless effort to promote my book. I've crafted some very special vectors for you. If you like them please purchase my book to read more. amazon.com/dp/B0BRD9B3GS
Gareth Heyes \u2028 tweet media
English
10
46
262
45.3K
Harel
Harel@H4R3L·
@MtnBer made me a new profile pic :)
Harel tweet media
English
1
0
6
407
Matan Berson
Matan Berson@MtnBer·
@j_zere Nice bug! It’s always fun to read about creative chains like this
English
1
0
9
1.3K
Matan Berson retweetledi
zere
zere@j_zere·
Just published my first blog post "Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover" You can read the full write-up here: zere.es/posts/cache-de…
English
26
141
588
49.7K
Matan Berson retweetledi
sudi
sudi@sudhanshur705·
Last year I found a XSS bug in Google IDX here's a detail writeup about it. Hope you will enjoy it's kinda lengthy :p Shoutouts to @MtnBer for finding the original bug in Gitlab and @kl_sree @sivaneshashok for the required chains to complete the exploit. sudistark.github.io/2025/07/02/idx…
English
13
86
373
25.5K
Matan Berson retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4
Kévin GERVOT (Mizu) tweet media
English
12
172
460
42.2K
Matan Berson retweetledi
Jorian
Jorian@J0R1AN·
Just found an interesting way to bypass some nonce-based CSPs and made a small XSS challenge with an exploitable scenario. See if you can find it before I tell! Source JS: gist.github.com/JorianWoltjer/… URL: greeting-chall.jorianwoltjer.com Found a solution? Please DM to avoid spoilers, thanks!
Jorian tweet media
English
3
25
153
16.4K
Matan Berson
Matan Berson@MtnBer·
@rebane2001 @ProtonMail Yep, I got $600 for a 1-click session takeover which is weird considering their whole brand is being privacy-focused. At least the security team was nice to work with
English
2
0
114
2.4K
Rebane
Rebane@rebane2001·
the @ProtonMail bug bounty rewards are incredibly low!? if you're a greyhat with a data leak bug you're NOT gonna take the $200 from proton when you could make literally 100x that selling it to someone with questionable ethics that hates journalists
Rebane tweet media
English
14
12
433
16.8K
Matan Berson retweetledi
Yaniv Nizry
Yaniv Nizry@YNizry·
[2/2] Meaning that if you have a file write and can't control the extension and the extension doesn't correlate to any Content-Type (let's say .abc), you can add .html to the file name (filename.html.abc) and httpd will serve it as text/html
English
1
1
10
1.4K
Matan Berson retweetledi
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
The vector: <svg><title><![CDATA[--></title><img src onerror=alert(1)>]]>
Română
0
3
16
2.5K
Matan Berson retweetledi
Jorian
Jorian@J0R1AN·
The legendary @joaxcar made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below: jorianwoltjer.com/blog/p/hacking…
English
1
28
164
8.2K
Matan Berson retweetledi
Gal Weizman
Gal Weizman@WeizmanGal·
Got back last week from Tokyo🇯🇵 where I caught @renbou & @Slonser's talk with @kumavis_ Being part of the web/browser/JavaScript security niche from the perspective of crypto wallets specifically, felt like a talk to not miss Here's what I learned 🧵 x.com/neploxaudit/st…
Gal Weizman tweet media
Neplox@neploxaudit

Thank you to everyone who came to see the first iteration of our talk IRL @secconctf ❤️ And we'd like to express additional gratitude to @WeizmanGal and @kumavis_ of @MetaMask for going out of their way to visit our talk and show how much they care for security.

English
3
9
32
6K
Jorian
Jorian@J0R1AN·
@xdeludnard @MtnBer @XssPayloads ^^ Exactly right, if you test your naive approach it won't work on Firefox. The method I (and 0x999) shared both don't require interaction, the popup blocker doesn't block these because it overwrites the current window.
English
2
0
1
174