home tags events about login
one honk maybe more

benjojo posted 02 Mar 2025 12:15 +0000

While filling out the Malaysian digital landing card stuff, I noticed the infosec equivalent of the snake from adam and eve offering me to possible explore cyber-crimes to a country I am about to visit.

(I didn't check)

a screenshot of a browser, highlighting the you around which appears to be html, underneath it is a part of the web page that would correspond with that html in the url bar

benjojo replied 02 Mar 2025 12:29 +0000
in reply to: https://chaos.social/users/nblr/statuses/114092819373524858

@nblr "nice". Given how XSS typically goes (and _boy_ do I know, given I was the single WAF guy at Cloudflare from ~2015-2017), I bet there is some funny XSS golf that would work here.

Back then, every time I wrote some XSS WAF patch there was a rat race to discover some new, innovative, and cursed way browsers can run javascript.