Advertisement Β· 728 Γ— 90

Posts by bubu

Preview
Top 10 web hacking techniques of 2025 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.

The Annual @portswiggerres.bsky.social Web Hacking Techniques Top 10 is now open for voting. If you believe my research β€œPermission Hijacking at Scale” adds value to the community, I’d be thankful for your vote.

portswigger.net/polls/top-10...

3 months ago 1 0 0 0

2026 has arrived. I’m exploring job opportunities and projects. Feel free to reach out.

3 months ago 1 0 0 0

pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!

Please please please share to spread the news - thank you!

6 months ago 20 17 1 3
Preview
Matrix.org Matrix, the open protocol for secure decentralised communications

So: the matrix.org database secondary lost its FS due to a RAID failure earlier today (11:17 UTC). Then, we lost the primary at 17:26. We're trying to restore the primary DB FS (which could be fastish), while also doing a point-in-time backup restore from last night (which takes >10h).

7 months ago 101 28 11 13
Post image

Excited to share that I’ll be speaking at #DefCampRO in November. See you there! πŸ‡·πŸ‡΄

7 months ago 0 0 0 0
Blink: Intent to Ship: Escape "<" and ">" in attributes on serialization Blink: Intent to Ship: Escape "<" and ">" in attributes on serialization

Blink: Intent to Ship: Escape "<" and ">" in attributes on serialization

11 months ago 2 2 0 0

That's me!

11 months ago 0 0 0 0
Blink: Intent to Deprecate and Remove: Remove auto-detection of ISO-2022-JP charset in HTML Blink: Intent to Deprecate and Remove: Remove auto-detection of ISO-2022-JP charset in HTML

Blink: Intent to Deprecate and Remove: Remove auto-detection of ISO-2022-JP charset in HTML

1 year ago 6 1 0 0

Thanks! I noticed this two months ago, and I thought they completely removed the option to see the source.

1 year ago 0 0 1 0

Yeah hahahahaha but from the full spec document, not including the header,
Firefox and Safari, IIRC, implement more or less the rest of stuff ;)

1 year ago 0 0 0 0
Advertisement

I completely agree, but are the standards that regulate the rest of specs that define a permission πŸ˜…

1 year ago 1 0 1 0

I'll take a look, thanks :)
Btw, when do you plan to deploy PP header? xD

1 year ago 0 0 1 0

Hope Bluesky adds bookmarks soon. I can't wait to have hundred of bookmarks I’ll never read, while lying to myself that I will.

1 year ago 0 0 0 0
You Shall Not Get Access πŸ§™πŸ»β€β™‚οΈ: Browser Permissions | WebSec! Web Security Educational Blog

I posted a blog about how browser permissions work. albertofdr.github.io/web-security...

1 year ago 6 2 1 0
facebook error

facebook error

netflix error

netflix error

okta error

okta error

whatsapp error

whatsapp error

Handling Cookies is a Minefield:

Inconsistencies in the HTTP cookie specification and its implementations have caused a situation where countless websites (including Facebook, Netflix, Okta, WhatsApp, Apple, etc.) are one small mistake away from locking their users out.

grayduck.mn/2024/11/21/h...

1 year ago 168 53 12 8
WebSec! Web Security Educational Course

From time to time I write about web/browser stuff here (albertofdr.github.io/web-security...) and post about CTF writeups (albertofdr.github.io/post/hkcert-...). That said, @ericlaw.bsky.social should definitely be on the list!

1 year ago 2 0 0 0
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty -  Mikhail Shcherbakov
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov YouTube video by DEFCONConference

If you missed it, my #DEFCON talk "Exploiting the Unexploitable: Insights from the Kibana Bug Bounty" is now live on YouTube!

youtu.be/H-bhmSwnRdY

1 year ago 13 6 1 1
Post image

This one is also funny!

1 year ago 1 0 0 0
The 2024 Web Almanac The Web Almanac is an annual state of the web report combining the expertise of the web community with the data and trends of the HTTP Archive.

🚨 Introducing the 2024 Web Almanac, our annual "state of the web" report!

πŸ”– almanac.httparchive.org/en/2024/

21 chapters (11 publishing today, the rest to follow)
65 contributors for today's chapters (more to follow)
17M websites analyzed
83 TB of data processed
628 queries written

1 year ago 70 39 5 14