Sabitlenmiş Tweet

Just released my blog post "Bidding Like a Billionaire - Stealing NFTs With 4-Char CSTIs"! It's about a very impactful and technically interesting client-side bug I found in a major NFT site.
matanber.com/blog/4-char-cs…
English
Matan Berson
253 posts

@MtnBer
Hacker and bug bounty hunter mostly focusing on client-side security. h1-702 Vigilante, h1-65 Eliminator, AWC23 Best New Hacker




I've released a DOMLogger++ config that helps detect any replacements occurring in a DOMPurify output by inserting and tracking a canary value at runtime. I think it highlights how useful DOMLogger++ can be for tracking JS execution :D 👉 github.com/kevin-mizu/dom… 1/3





















Thank you to everyone who came to see the first iteration of our talk IRL @secconctf ❤️ And we'd like to express additional gratitude to @WeizmanGal and @kumavis_ of @MetaMask for going out of their way to visit our talk and show how much they care for security.


