MKSB(en)
Masato Kinugawa's Security Blog /
@kinugawamasato
Sunday, April 10, 2016
Abusing docmode inheritance: EasyXDM 2.4.19 DOMXSS
›
In this post, I would like to explain an XSS issue of EasyXDM 2.4.19. I reported it and it was fixed by the developer. If you are users, ...
32 comments:
Friday, January 29, 2016
XSS using Google Toolbar's command
›
In this post, I would like to share two XSSes in toolbar.google.com. I discovered in June 2015 and it has already been fixed. Those bugs ar...
28 comments:
Wednesday, December 16, 2015
X-XSS-Nightmare: XSS Attacks Exploiting XSS Filter
›
In this post, I would like to share XSS attack using IE's XSS filter. This issue was fixed in the December patch by Microsoft. (CVE-20...
27 comments:
Friday, November 20, 2015
My Presentation at AVTOKYO2015: Bug-hunter's Sorrow
›
In this post, I'd like to share my slides in AVTOKYO2015 . AVTOKYO2015 is a computer security conference which was held in November 14, ...
18 comments:
Friday, October 23, 2015
CSS based Attack: Abusing unicode-range of @font-face
›
In this post, I would like to share about new CSS based attack with unicode-range descriptor of @font-face rule . Using this technique, an...
37 comments:
Tuesday, September 29, 2015
Bypassing IE's XSS Filter with HZ-GB-2312 escape sequence
›
I would like to share IE XSS Filter bypass with escape sequence of HZ-GB-2312 encoding. To use this vector, we need the target page's ...
23 comments:
Wednesday, August 26, 2015
CVE-2015-4483: Firefox Mixed Content Blocker bypass with feed: protocol
›
Today, I would like to share details of CVE-2015-4483. This bug was fixed in Firefox 40. Security advisory is here . Usually, Firefox can ...
21 comments:
‹
›
Home
View web version