Xiety

588 posts

Xiety banner
Xiety

Xiety

@_Xiety

Securing the internet one bug at a time :) | Top 25 @YesWeHack | Founder Of @BountyBrief

Ontario, CA Katılım Eylül 2021
321 Takip Edilen753 Takipçiler
Xiety retweetledi
trace37
trace37@trace37_labs·
Woke up this morning thinking "It's Thursday — no XSS reported this week... ... what will I do for PAYLOAD OF THE WEEK?" Started on a new target last night. Woke up VERY early and found this: Confirmed DOM XSS → theoretical ATO (still working on that!). Cloudflare WAF bypassed. The bypass is the interesting part: onerror=alert(1) → 403 onerror%0c=alert(1) → 200 Note: one character: %0c is a form feed. Cloudflare matches onerror= literally. The HTML spec treats form feed as whitespace — so onerror\x0c= is a valid event handler that CF never sees. Once past the WAF, the XSS chain was wide open: - URLSearchParams → Vuex store → v-html / innerHTML - No sanitisation at any step. - CSP was report-only — never enforced, so nothing blocked execution. - Confirmed in all browsers. No auth required. - Single link from the browser. Sanitised explanation in the image - plus time-stamped ALERT from just moments ago. You're watching XSS live!! Report to h1 almost drafted but on hold as I look to escalate to full ATO. Things worth adding to your methodology: 1. When a WAF blocks your event handler, try whitespace variants before moving on. Form feed, vertical tab, null byte. CF won't always catch them. 2. Vue apps using v-html are worth tracing. It compiles straight to innerHTML. Follow the data into the store. 3. If you see Content-Security-Policy: ... report-only — that's not protection. That's a log file 😄
trace37 tweet mediatrace37 tweet media
trace37@trace37_labs

Another day, another WAF bypassed, XSS reported and bounty awaited. param=%22%7D%2C%22*%22)%3Bvar%20d%3DglobalThis%5B%22docu%22%2B%22ment%22%5D%3Bd.body.innerText%3Dd%5B%22do%22%2B%22main%22%5D%2B%22%3A%20%22%2Bd%5B%22coo%22%2B%22kie%22%5D%3B%2F%2F COME ON WAF's... who's next...?!

English
3
7
58
4.9K
Xiety
Xiety@_Xiety·
My nana is trying to win the fight against stage 4 cancer. Anything helps. Share or a donation helps us out tremendously. gofundme.com/f/Help-Us-Make…
English
0
0
0
59
Evan Klein
Evan Klein@EvanKlein338226·
@_Xiety The "informative" mark on valid IDORs is the most frustrating part of this game. Always ask for clarification on scope and push back with clear impact. If they can't articulate why it's not a real issue, escalate.
English
1
0
1
218
Xiety
Xiety@_Xiety·
Great way to start the day with a Critical IDOR as Informative!
Xiety tweet media
English
6
1
96
6.2K
Tal_buggcrowd(parody)
Tal_buggcrowd(parody)@EubardWells·
@_Xiety @_MrPlanB You have to mention them about your @yeswehack profile coz 0_day_pilot might have added your profile to AI sllop groups and he keeps doing it for many researchers where they blindly close submission as "N/A"
English
1
0
1
91
Xiety
Xiety@_Xiety·
@_MrPlanB Just a better way to say get scammed, We will fix it and not reward lol used to it.
English
1
0
3
144
s0rte
s0rte@_MrPlanB·
@_Xiety An exceptional as known issue is wild 🥲
English
1
0
1
145
Xiety
Xiety@_Xiety·
@_MrPlanB “Known issue” but its not written in the known issues on the program so Im confused
English
1
0
4
548
s0rte
s0rte@_MrPlanB·
@_Xiety Reason of closure?
English
1
0
0
415
Tal_buggcrowd(parody)
Tal_buggcrowd(parody)@EubardWells·
@_Xiety @intigriti Is that my newbie acquaintance 0_day_pilot or commanderstax. They are living in illusions due to huge AI slop. Even this world is a simulation for them!!! No wonder They watched matrix movie series too much and still got high !!! @intigriti
English
1
0
2
57
Xiety
Xiety@_Xiety·
I have an endpoint where I can inject malicious content into a QR code. Inject and pre-fill messages to numbers which is a toll rate number I can set up. Also I can redirect to a malicious site, make the user call a number etc. Impactful?! @intigriti Triage says no. LOL
English
1
0
2
331
Xiety
Xiety@_Xiety·
To my bug bounty/infosec family: My Nana was hit with a Stage 4 lung cancer diagnosis. It’s aggressive and the costs are stacking up fast. I’m grinding to cover what I can, but I’m asking for a hand. please consider sharing please! gofund.me/452ed087e
English
5
2
22
769
Xiety
Xiety@_Xiety·
I have an endpoint that allows you to download a users Privately listed video not *youtube* btw. Just by visiting the link. Improper Access
English
0
0
5
464
Xiety
Xiety@_Xiety·
@s4dmach1ne Not toxic at all, If you lack and don’t submit someone else is going to. Won’t always be there waiting for you
English
0
0
0
51
s4dmach1ne
s4dmach1ne@s4dmach1ne·
@_Xiety the FOMO is real and that mindset is toxic imo
English
1
0
1
52
Xiety
Xiety@_Xiety·
Each day you decide to miss on hunting for bugs increases your chances of dupes. #Bugbounty
English
1
2
27
1.2K
Xiety
Xiety@_Xiety·
Is the 0day_pilot on @intigriti a bot? They just closed a html injection and IDOR leaking PII as information/ Closed lmao
English
6
0
30
4.8K
Xiety
Xiety@_Xiety·
@intigriti why is oday_pilot closing impactful bugs? PII disclosure + html injection? Makes me want to rethink your platform
English
0
0
2
145