![slonser Profile](https://pbs.twimg.com/profile_images/1731206774772973568/MzaCmwZO_x96.jpg)
slonser
@slonser_
Followers
2K
Following
161
Statuses
84
@C4TBuTS4D CTF team. Security Researcher at Solidlab. Web3 research at @neploxaudit
Joined December 2023
@WeizmanGal Some of the examples that will be shown and the anti-patterns of development are applicable to Metamask; however, Metamask is quite secure and one of the few wallets where a complete exploitation chain could not be achieved. ;)
1
1
11
Great talks! I'm happy that @kevin_mizu research made it into the top 10—he deserves it. A bit sad that I didn’t make it into the top 10, though. It seems that research related to Chrome isn’t very interesting to the community, so maybe I should try something different in 2025.
4
1
50
RT @d4d89704243: Introducing the Cookie Sandwich, a tasty technique to steal HttpOnly cookies using legacy RFC features:
0
85
0
@kinugawamasato Yeah, I know, I accidentally sent an unfinished example to the server while uploading another update :) I'm working on adapting a real example to make it less bulky and to avoid getting penalized for disclosure. Sorry about that.
0
0
2
@kinugawamasato Hi! Yes, in this case, it really isn't necessary. My mistake— I tried to oversimplify the example to make it easier to understand XD I am going to update the article with a different example, thanks for your help!
1
0
4
@TheGrandPew Yes, I didn’t phrase it quite correctly. Initially, I meant it in the context of rewriting the document object. I will revise the article and elaborate on this point in more detail. Thank you for your help!
0
0
2
RT @neploxaudit: Can you find an error in the following Chrome extension content scripts? If not, you might want to check out our knowledge…
0
3
0
@albinowax @kobi_hk Therefore, if you have access to modify headers (and can insert an arbitrary content-type), it's game over. You simply gain control over the Service Worker.
1
0
3
@kevin_mizu But there's a chance that the first part will make it into the top of 2024, and the second one into the top of 2025 XD
1
0
1