ThomasOrlita Profile Banner
Thomas Orlita Profile
Thomas Orlita

@ThomasOrlita

Followers
702
Following
278
Statuses
48

web & browser security https://t.co/jDpG6vMPDr

United Kingdom, Czech Republic
Joined September 2016
Don't wanna be here? Send us removal request.
@ThomasOrlita
Thomas Orlita
2 months
0
0
0
@ThomasOrlita
Thomas Orlita
6 months
@lbherrera_ seems like the link is down, unless that's part of the challenge haha
Tweet media one
1
0
1
@ThomasOrlita
Thomas Orlita
6 months
@joaxcar @kevin_mizu (and false negatives)
0
0
0
@ThomasOrlita
Thomas Orlita
10 months
@garethheyes Ohh interesting! Btw, I replaced `$[chr]` with `String.fromCodePoint($[i])` in the templates, as otherwise it causes incorrect results because the characters aren't escaped.
1
0
0
@ThomasOrlita
Thomas Orlita
1 year
@stevekrouse @NotionHQ using a ccTLD like this seems like a security risk, especially that has seized a domain before
0
0
1
@ThomasOrlita
Thomas Orlita
1 year
RT @ndevtk: Bug write-up for Google Extensions thanks @ThomasOrlita and others for the help :) this writeup does in…
0
117
0
@ThomasOrlita
Thomas Orlita
3 years
Overview of different vulnerabilities in Google's new web-based collaboration tool Threadit: XSS, Clickjacking, ACL bypass, Info leak... #BugBounty #InfoSec
0
10
27
@ThomasOrlita
Thomas Orlita
4 years
0
0
0
@ThomasOrlita
Thomas Orlita
4 years
@missoum1307 @PortSwigger Sign in regular Chrome, intercept and copy the Set-Cookie header from the response. In the embedded browser open intercept the response and include the copied Set-Cookie header.
0
0
1
@ThomasOrlita
Thomas Orlita
4 years
@AvidSec @filedescriptor Since the build is failing for some people, I've added the compiled version under the Releases tab. I'll also post a link to the extension on the Chrome Web Store once it's approved there, however that might take several weeks.
1
0
1
@ThomasOrlita
Thomas Orlita
4 years
@TeslaTheGod @filedescriptor This means you didn't build the extension. First you need to install the dependencies using `npm i` and then build it with `npm run build`. After that load the `public` folder.
1
0
0
@ThomasOrlita
Thomas Orlita
4 years
@TeslaTheGod @filedescriptor Can you elaborate?
1
0
0
@ThomasOrlita
Thomas Orlita
4 years
@h4x0r_dz @filedescriptor Hey, please make sure you ran `npm run build`
1
0
1
@ThomasOrlita
Thomas Orlita
4 years
RT @filedescriptor: Untrusted Types just got a new UI with better filtering options and features thanks to @ThomasOrlita! Check it out! h…
0
34
0
@ThomasOrlita
Thomas Orlita
4 years
Getting confidential information about upcoming Google Cloud products from unrestricted draft blog post images. #BugBounty #InfoSec
0
9
27
@ThomasOrlita
Thomas Orlita
5 years
Getting all 32000 email addresses of every registered user on s Crisis Map thanks to IDOR and incremental IDs. #BugBounty #InfoSec
0
5
27
@ThomasOrlita
Thomas Orlita
5 years
@spazef0rze Mě spíš zaujalo, že mi řekli, že správce hesel nedoporučují kvůli nějakému principu o alespoň dvou různých typů bezpečnostních faktorů, který musejí dodržovat ze zákona. Ale jak jsem se teď dočetl, správce hesel v tom článku sami doporučují.
Tweet media one
1
0
1