MKSB(en)

Masato Kinugawa's Security Blog / @kinugawamasato

Sunday, September 25, 2016

CVE-2016-4758: UXSS in Safari's showModalDialog

›
I would like to share about details of Safari's UXSS bug(CVE-2016-4758). This bug was fixed in Safari 10. https://support.apple.com/en...
331 comments:
Friday, July 15, 2016

Abusing XSS Filter: One ^ leads to XSS(CVE-2016-3212)

›
In the past, I talked about XSS attacks exploiting IE XSS filter in CODE BLUE, which is an information security conference in Japan. A simi...
33 comments:
Wednesday, May 18, 2016

XSS Auditor bypass using Flash and base tag

›
A few days ago, I was playing Chrome XSS Auditor bypass with Mario. Mario discovered this bypass: XSS Auditor Bypasses 05.2016 https://...
25 comments:
Sunday, April 10, 2016

Abusing docmode inheritance: EasyXDM 2.4.19 DOMXSS

›
In this post, I would like to explain an XSS issue of EasyXDM 2.4.19. I reported it and it was fixed by the developer. If you are users, ...
38 comments:
Friday, January 29, 2016

XSS using Google Toolbar's command

›
In this post, I would like to share two XSSes in toolbar.google.com. I discovered in June 2015 and it has already been fixed. Those bugs ar...
28 comments:
Wednesday, December 16, 2015

X-XSS-Nightmare: XSS Attacks Exploiting XSS Filter

›
In this post, I would like to share XSS attack using IE's XSS filter. This issue was fixed in the December patch by Microsoft. (CVE-20...
29 comments:
Friday, November 20, 2015

My Presentation at AVTOKYO2015: Bug-hunter's Sorrow

›
In this post, I'd like to share my slides in AVTOKYO2015 . AVTOKYO2015 is a computer security conference which was held in November 14, ...
18 comments:
‹
›
Home
View web version
Powered by Blogger.