Markdown parsing issue enables insertion of malicious tags and event handlers
https://hackerone.com/reports/299728
https://hackerone.com/reports/299728
HackerOne
HackerOne disclosed on HackerOne: Markdown parsing issue enables...
When markdown is being presented as HTML, there seems to be a strange interaction between _ and @ that lets an attacker insert malicious tags.
# Proof of Concept...
# Proof of Concept...
injectify
Perform advanced MiTM attacks on websites with ease.
https://github.com/samdenty99/injectify
Perform advanced MiTM attacks on websites with ease.
https://github.com/samdenty99/injectify
GitHub
GitHub - samdenty/injectify: Perform advanced MiTM attacks on websites with ease 💉
Perform advanced MiTM attacks on websites with ease 💉 - samdenty/injectify
Spyware.Sateto With the ability to steal bitcoin 😳
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=4833
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=4833
Nice job!
Exploiting CSRF on JSON endpoints with Flash
https://blog.appsecco.com/exploiting-csrf-on-json-endpoints-with-flash-and-redirects-681d4ad6b31b
Exploiting CSRF on JSON endpoints with Flash
https://blog.appsecco.com/exploiting-csrf-on-json-endpoints-with-flash-and-redirects-681d4ad6b31b