Post Aw9xTD2aZvSwriPMWG by [email protected] | |
More posts by [email protected] | |
Post #Aw8rtyDgzqXnpp1FLc by [email protected] | |
0 likes, 1 repeats | |
Remote code execution through js2py onCaptchaResulthttps://github.com/pyload/py… | |
Post #Aw8rtyL8YAV0CuVBx2 by [email protected] | |
0 likes, 1 repeats | |
@cR0w Aah the famous:"unsafe JavaScript evaluation vulnerability"Let … | |
Post #Aw9olWzUFDdcMdcQGu by [email protected] | |
0 likes, 1 repeats | |
@Sempf I know it would get me fired but I would love to push NoScript through t… | |
Post #Aw9v7P4owrqDunvUvo by [email protected] | |
0 likes, 1 repeats | |
@cR0w I had a client who did that! It was a small group - 15 people. Maybe. The… | |
Post #Aw9vONows5oqwVbBsu by [email protected] | |
0 likes, 1 repeats | |
@Sempf I can't even imagine how much would break now compared to before. Bu… | |
Post #Aw9vfQS8L4cW1q3OZU by [email protected] | |
0 likes, 1 repeats | |
@cR0w @Sempf Would you replace it with another, saner scripting language? WASM?… | |
Post #Aw9vpuNJwWzNj8njJQ by [email protected] | |
0 likes, 1 repeats | |
@mttaggart @Sempf I'm simple so I would stick with HTML and CSS. And more T… | |
Post #Aw9wCzEG3x0zRQZCMK by [email protected] | |
0 likes, 1 repeats | |
@cR0w @Sempf I would prefer to dream of a better way to run code in the browser… | |
Post #Aw9wPKwLARpIFg4hmK by [email protected] | |
0 likes, 1 repeats | |
@mttaggart @Sempf To me, any client-side code exec is the issue. It's defin… | |
Post #Aw9xTD2aZvSwriPMWG by [email protected] | |
0 likes, 1 repeats | |
@cR0w @Sempf and it locks the entire org out of CF. Win-win. | |
Post #Aw9xaq5RnvnhzYNp8y by [email protected] | |
0 likes, 1 repeats | |
@cR0w @mttaggart I could not agree more. Cute user interface tricks are fine, b… | |
Post #Aw9zjUqcLA5adNhcRc by [email protected] | |
0 likes, 1 repeats | |
@Sempf @cR0w @codinghorror I agree validation should be server side, but I quit… | |
Post #AwA0kkaFQ5NXgMCvRI by [email protected] | |
0 likes, 1 repeats | |
@mttaggart @cR0w @codinghorror Somewhere in the OWASP archive there is a copy o… |