Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Universal CSP strict-dynamic bypass in Firefox - 55

Masato KinugawaPosted 6 Years Ago
  • The content-security-policy is a protection that helps with HTML injection and XSS flaws with a website. A bypass for the CSP would bypass all these restrictions.
  • This seems to be a parser issue, that allows the loading of some file, given a previous XSS bug.
  • This feels like black magic... Dive into the parsing details if you are looking for a good time!