Daniel Thatcher

36 posts

Daniel Thatcher banner
Daniel Thatcher

Daniel Thatcher

@_danielthatcher

Researcher, and security person at @intruder_io. Hack dumber. He/him

Katılım Haziran 2018
257 Takip Edilen655 Takipçiler
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
@sudhanshur705 @strellic This can work at times, and I mention something similar in the next part (coming soon), though in most of the real-world webapps I've seen driving headless browsers there is a timeout enforced by the app which you can't lengthen this way.
English
1
0
1
98
sudi
sudi@sudhanshur705·
@_danielthatcher @strellic Also to solve that problem where pages are loaded for a short amount of time ,such slow load images can be used to make sure the attack can be completed without any time issues
sudi tweet media
English
1
0
1
138
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
Part 2 will be release on Wednesday, when I'm presenting the research at BHEU
English
0
0
1
295
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
@BlackHatEvents Whenever I try to submit my proposal, I get a 403 Forbidden. Is there anything I can do?
English
0
0
0
104
Black Hat
Black Hat@BlackHatEvents·
#BHEU 2023 Briefing Call for Papers closes tomorrow, August 2! Submit your proposal for the chance to share your research, knowledge & expertise at Black Hat Europe>> bit.ly/45ADELx
English
2
0
2
5.1K
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
A while ago I decided to try take on a big challenge and work out how to detect prototype pollution black-box. One thing I’m very happy with from this research is the simplicity of the solution I found
Intruder@intruder_io

Prototype pollution can be a dangerous bug, but it's hard to detect in real-world scenarios without the source code. In the latest blog, our researcher, @_danielthatcher, discusses a new technique for detecting prototype pollution in black-box situations:hubs.li/Q01Cs9L70

English
0
0
3
663
Daniel Thatcher retweetledi
mopman
mopman@mopman·
Why do I know so many Dan's in infosec? Is there something about the name Dan? I strongly advise being cautious of your data around anyone named Dan, until we work this out.
English
9
3
15
0
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
The technique isn’t new, but the vast majority of pentesters I’ve spoken to don’t know about it, so I thought it worth sharing with an example from a pentest. I’ve also created a tool to help you exploit this issue github.com/intruder-io/gu…
English
1
1
12
0
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
@notdurson Dan is also a wonderful person. It was a lot of fun. Hopefully we see each other again next year
English
0
0
1
0
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
Heading off to Vegas for the first time. If you see me about, say hi. I’m the lanky blond British guy with round black glasses.
English
1
0
2
0
Daniel Thatcher
Daniel Thatcher@_danielthatcher·
This example works by using the self-XSS to set a session cookie with a limited path so that the self-XSS will still load when the victim logs back into their account. The self-XSS can then access the rest of the application as the victim, so is effectively regular XSS.
English
2
0
0
0