Client-Side SSRF to Credential Theft via Exported Android Activity
How reading one exported Activity by hand, following an unvalidated URL field, and misreading the impact twice led to a one-tap session token leak any co-installed app could trigger.
// the blog
Deep dives, notes and field reports from the collective.
// latest
How reading one exported Activity by hand, following an unvalidated URL field, and misreading the impact twice led to a one-tap session token leak any co-installed app could trigger.
// more writing
A clean reflected XSS on an auth-less subdomain that topped out at alert(1), and the investigation that turned it into a critical account...
A reflected HTML injection my partner was about to file as low. Here is the investigation that turned it into an account takeover, includ...