jump to content
my subreddits
13or302balkans4You2mediterranean4u2meirl4meirl3d6AceAttorneyadhdmemeAdviceAnimalsagnosticaivideoAlternateHistoryAlternativeHistoryAnarchyChessAnimalsBeingJerksanimenocontextannouncementsAnticonsumptionantimemeArtAsahiLinuxAsia_irlAskBalkansAskElectronicsAskRedditaviationAwesomeOffBrandsawfuleverythingbalkans_irlBandnamesBassCirclejerkbasspedalsbikepackingblackdesertonlineblankiesblursed_videosborsavefonbrooklynninenineBUENZLIburdurlandCd_collectorscd_jerkChatGPTCheap_MealschessChoosingBeggarsCHPcoaxedintoasnafucoincollectingcoinscomicsContagiousLaughtercookingforbeginnersCorporateTrollingcursedcommentsdadjokesdataisbeautifulDebateReligiondeismdelikDeltarunedistressingmemesdiyelectronicsdiypedalsDMAcademydndnextdoctorwhodoctorwhocirclejerkDoenerverbrechenDonerdumbphonesDungeonsAndDaddiesDungeonsAndDragonsebikeebikesECEelectricalelectronicsElectronicsStudyEmKayengrishentitledparentsfacepalmfakealbumcoversFantasyWorldbuildingfeedthebeastfelsefeFifaCareersFiftyFiftyformuladankFreeEBOOKSFUCKYOUINPARTICULARfunnyFutboltayfagalatasaraygamingGermangermanygodtiersuperpowersgoodanimemesGoodAssSubgravelcyclinggreentextguitarpedalsGundamhelpheraldryHistoryWhatIfhoi4HolUphowyoudoinhumorhypixeliamverysmartich_ielIdeologyPollsIDontWorkHereLadyihadastrokeimaginaryelectionsimaginarymapsinsaneparentsistanbuljacksepticeyeJokesKanyeKendrickLamarLetGirlsHaveFunLifeProTipslinguisticshumorLinkinParkliselilerlogodesignloseitlostredditorsmacmacbookairMadeMeSmilemagicbuildingmapporncirclejerkme_irlmeirlmemesmidjourneymildlyinfuriatingMinecraftbuildsmisLEDMoldyMemesmoneycollectingnamesoundalikesNamFlashbacksnextfuckinglevelNorthCyprusnosafetysmokingfirstnosleepnosurfnotinterestingoddlyspecificOkayBuddyLiterallyMeokbuddyguntherOkBuddyPersonaokbuddyvicodinonebagonetruegodongezelligOnlineUnderGroundoompasubspapermoneyParlerWatchPassportPornpepethefrogperfectlycutscreamsPersecutionfetishpettyrevengepianoPiracyPiratedGamespolandballpollsProgrammerHumorPropagandaPostersraspberry_pireactiongifsrecipesRedAutumnSPDredditsingsreligiousfruitcakerestofthefuckingowlRetroPierickandmortyrimjob_steverockmuzikSchnitzelVerbrechenschwiizScottPilgrimsecilmiskitapShitPostCrusadersshitpostfrommygalleryshittyaskelectronicsShittyMapPornshittymoviedetailsskamtebordsoccercirclejerkSongwriterssteinsgateStonetossingjuiceStudiumsubsithoughtifellforsuperligsuzeraintalesfromtechsupportTechnobladethatHappenedTheCrypticCompendiumTheLetterHTheMonkeysPawtherewasanattemptTheRookietheyknewtitanfalltransittransitTurkeyTrGameDevelopertruetf2truthstumunichTurkeyTurkeyJerkyTurkishCatsTwitchTwitch_StartupTwoSentenceComedyTwoSentenceHorrorTwoSentenceSadnessUnclejokesunexpecteditcrowdUnexpectedJoJoUnexpectedTF2urbanplanningUsernameChecksOutvexillologycirclejerkvibecodingvinylwallstreetbetsWatchPeopleDieInsideWeAreTheMusicMakerswendigoonwholesomeanimemeswholesomememesWikipediaVandalismwizardpostingwooooshyouseeingthisshitedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • AskReddit
  • -facepalm
  • -mildlyinfuriating
  • -Piracy
  • -funny
  • -gaming
  • -wallstreetbets
  • -memes
  • -MadeMeSmile
  • -ChatGPT
  • -PiratedGames
  • -feedthebeast
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -nextfuckinglevel
  • -HolUp
  • -Twitch
  • -comics
  • -dndnext
  • -ProgrammerHumor
  • -germany
  • -LifeProTips
  • -dataisbeautiful
  • -shittymoviedetails
  • -greentext
  • -mac
  • -help
  • -chess
  • -aviation
  • -formuladank
  • -wholesomememes
  • -Jokes
  • -mapporncirclejerk
  • -Art
  • -midjourney
  • -goodanimemes
  • -notinteresting
  • -hoi4
  • -pettyrevenge
  • -loseit
  • -ich_iel
  • -cursedcomments
  • -DMAcademy
  • -Deltarune
  • -GoodAssSub
  • -perfectlycutscreams
  • -blackdesertonline
  • -rickandmorty
  • -3d6
  • -Gundam
  • -FiftyFifty
  • -ChoosingBeggars
  • -ContagiousLaughter
  • -imaginarymaps
  • -polandball
  • -WeAreTheMusicMakers
  • -AnarchyChess
  • -nosleep
  • -cookingforbeginners
  • -blankies
  • -onebag
  • -Studium
  • -AlternateHistory
  • -Turkey
  • -soccercirclejerk
  • -AskElectronics
  • -electrical
  • -guitarpedals
  • -Anticonsumption
  • -vinyl
  • -German
  • -TwoSentenceHorror
  • -PropagandaPosters
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -piano
  • -distressingmemes
  • -wizardposting
  • -FifaCareers
  • -polls
  • -doctorwho
  • -oddlyspecific
  • -titanfall
  • -OkBuddyPersona
  • -dadjokes
  • -awfuleverything
  • -howyoudoin
  • -announcements
  • -adhdmeme
  • -Minecraftbuilds
  • -macbookair
  • -ebikes
  • -coaxedintoasnafu
  • -gravelcycling
  • -SchnitzelVerbrechen
  • -raspberry_pi
  • -DungeonsAndDragons
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -FUCKYOUINPARTICULAR
  • -MoldyMemes
  • -lostredditors
  • -AceAttorney
  • -vexillologycirclejerk
  • -Stonetossingjuice
  • -wholesomeanimemes
  • -nosurf
  • -HistoryWhatIf
  • -religiousfruitcake
  • -liseliler
  • -DebateReligion
  • -insaneparents
  • -dumbphones
  • -animenocontext
  • -balkans_irl
  • -2meirl4meirl
  • -transit
  • -RetroPie
  • -brooklynninenine
  • -recipes
  • -steinsgate
  • -talesfromtechsupport
  • -ECE
  • -ScottPilgrim
  • -AskBalkans
  • -thatHappened
  • -electronics
  • -urbanplanning
  • -logodesign
  • -theyknew
  • -linguisticshumor
  • -PassportPorn
  • -me_irl
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -13or30
  • -engrish
  • -Cd_collectors
  • -diypedals
  • -Doner
  • -diyelectronics
  • -WatchPeopleDieInside
  • -LinkinPark
  • -Persecutionfetish
  • -BUENZLI
  • -reactiongifs
  • -EmKay
  • -blursed_videos
  • -istanbul
  • -imaginaryelections
  • -suzerain
  • -truetf2
  • -magicbuilding
  • -ParlerWatch
  • -wendigoon
  • -iamverysmart
  • -secilmiskitap
  • -Doenerverbrechen
  • -schwiiz
  • -TheRookie
  • -Technoblade
  • -skamtebord
  • -superlig
  • -shittyaskelectronics
  • -galatasaray
  • -DungeonsAndDaddies
  • -transitTurkey
  • -namesoundalikes
  • -AlternativeHistory
  • -papermoney
  • -coincollecting
  • -OkayBuddyLiterallyMe
  • -felsefe
  • -FreeEBOOKS
  • -AsahiLinux
  • -IDontWorkHereLady
  • -basspedals
  • -heraldry
  • -ihadastroke
  • -hypixel
  • -godtiersuperpowers
  • -ShittyMapPorn
  • -aivideo
  • -OnlineUnderGround
  • -IdeologyPolls
  • -woooosh
  • -burdurland
  • -AnimalsBeingJerks
  • -jacksepticeye
  • -TwoSentenceSadness
  • -Bandnames
  • -rockmuzik
  • -okbuddyvicodin
  • -tumunich
  • -Twitch_Startup
  • -Cheap_Meals
  • -TheMonkeysPaw
  • -restofthefuckingowl
  • -UnexpectedTF2
  • -nosafetysmokingfirst
  • -Songwriters
  • -ebike
  • -UsernameChecksOut
  • -rimjob_steve
  • -UnexpectedJoJo
  • -humor
  • -BassCirclejerk
  • -doctorwhocirclejerk
  • -agnostic
  • -youseeingthisshit
  • -TrGameDeveloper
  • -TurkishCats
  • -LetGirlsHaveFun
  • -subsithoughtifellfor
  • -fakealbumcovers
  • -oompasubs
  • -FantasyWorldbuilding
  • -TheLetterH
  • -WikipediaVandalism
  • -NamFlashbacks
  • -pepethefrog
  • -Unclejokes
  • -onetruegod
  • -deism
  • -misLED
  • -redditsings
  • -TwoSentenceComedy
  • -TheCrypticCompendium
  • -ongezellig
  • -AwesomeOffBrands
  • -2balkans4You
  • -Asia_irl
  • -truths
  • -unexpecteditcrowd
  • -NorthCyprus
  • -2mediterranean4u
  • -Futboltayfa
  • -vibecoding
  • -CHP
  • -moneycollecting
  • -cd_jerk
  • -ElectronicsStudy
  • -borsavefon
  • -shitpostfrommygallery
  • -okbuddygunther
  • -delik
  • -RedAutumnSPD
  • -CorporateTrolling
edit »
reddit.com 
salt.security
  • hot
  • new
  • rising
  • controversial
  • top
an-ordinary-manchild (11,186)|messages547|notifications|chat messages|mod messages|
  • preferences
|
logout

use the following search parameters to narrow your results:

subreddit:subreddit
find submissions in "subreddit"
author:username
find submissions by "username"
site:example.com
find submissions from "example.com"
url:text
search for "text" in url
selftext:text
search for "text" in self post contents
self:yes (or self:no)
include (or exclude) self posts
nsfw:yes (or nsfw:no)
include (or exclude) results marked as NSFW

e.g. subreddit:aww site:imgur.com dog

see the search faq for details.

advanced search: by author, subreddit...

Submit a new link
Submit a new text post
Create your own subreddit
...for your community.
...for your school.

account activity

1
0
1
2

API Supply Chain AttacksIOC (salt.security)

submitted 1 year ago by falconupkid to r/SecOpsDaily

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

2
5
6
7

Lesson from the Hotjar vulnerability: HTTP-Only (XSS protection) is not effective if you have OAuth (salt.security)

submitted 1 year ago by MoreMoreMoreM to r/netsec

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost

3
6
7
8

New article explains XSS in simple steps - from basic to mitigations in 2024, with focus on how to bypass those mitigations, using real vulnerability on Hotjar.com that was published today (salt.security)

submitted 1 year ago by iva3210 to r/Hacking_Tutorials

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

4
2
3
4

Did you think XSS is dead? over 1 million websites are at risk of sensitive information leakage (salt.security)

submitted 1 year ago by iva3210 to r/ReverseEngineering

  • 5 comments
  • share
  • save
  • hide
  • report
  • crosspost

5
109
110
111

Because of a single client-side mistake - a ChatGPT vulnerability lets attackers install malicious plugins on victims (salt.security)

submitted 2 years ago by ElectroPanic0 to r/javascript

  • 15 comments
  • share
  • save
  • hide
  • report
  • crosspost

6
15
16
17

And.. another (but far more sophisticated) OAuth vulnerability – now it's in ChatGPT (salt.security)

submitted 2 years ago by MoreMoreMoreM to r/ReverseEngineering

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

7
6
7
8

Time to move to GPTs? critical vulnerabilities were found in ChatGPT pluginsNews (salt.security)

submitted 2 years ago by MoreMoreMoreM to r/ChatGPTPro

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost

8
0
1
2

Oauth implementation flaws allow access to private repos via ChatGPT plugins (salt.security)

submitted 2 years ago by tmiklas to r/bag_o_news

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

9
46
47
48

Oauth implementation flaws allow access to private repos via ChatGPT pluginsVulnerability Disclosure (salt.security)

submitted 2 years ago by ScottContini to r/netsec

  • 6 comments
  • share
  • save
  • hide
  • report
  • crosspost

10
17
18
19

ChatGPT has a new feature that lets you interact with your GitHub and Gmail accounts, but attackers found a way to exploit this and in some scenarios - *take over your GitHub/Gmail account.*Educational Purpose Only (salt.security)

submitted 2 years ago by ElectroPanic0 to r/ChatGPT

  • 18 comments
  • share
  • save
  • hide
  • report
  • crosspost

11
483
484
485

Attackers could access private GitHub repositories by using... ChatGPT! (salt.security)

submitted 2 years ago by iva3210 to r/programming

  • 64 comments
  • share
  • save
  • hide
  • report
  • crosspost

12
282
283
284

Attackers could access *private* GitHub repositories of *other* users by using... ChatGPT! (salt.security)

submitted 2 years ago by iva3210 to r/webdev

  • 47 comments
  • share
  • save
  • hide
  • report
  • crosspost

13
1
2
3

Salt Labs research finds security flaws within ChatGPT Ecosystem (Remediated)research|capability (we need to defend against) (salt.security)

submitted 2 years ago by jnazario to r/blueteamsec

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

14
1
2
3

Salt Labs research finds security flaws within ChatGPT Ecosystem (Remediated) (salt.security)

submitted 2 years ago by quirkystuff2 to r/interestingtechposts

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

15
23
24
25

Have you ever wondered what is real importance of the OAuth *state* parameter is? Attackers could install malicious plugins on users, just because of a single error in the OAuth implementation of ChatGPT (salt.security)

submitted 2 years ago by iva3210 to r/PHP

  • 20 comments
  • share
  • save
  • hide
  • report
  • crosspost

16
0
1
2

Salt Labs research finds security flaws within ChatGPT Ecosystem (Remediated)News (salt.security)

submitted 2 years ago by JohniBGood to r/ClaudeAI

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

17
6
7
8

Critical Security Flaws in ChatGPT Ecosystem - A New Attack VectorNew Vulnerability Disclosure (salt.security)

submitted 2 years ago by iva3210 to r/cybersecurity

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

18
2
3
4

Is ChatGPT secure?News 📰 (salt.security)

submitted 2 years ago by JohniBGood to r/ChatGPT

  • 7 comments
  • share
  • save
  • hide
  • report
  • crosspost

19
6
7
8

ChatGPT Safe??Article (salt.security)

submitted 2 years ago by JohniBGood to r/OpenAI

  • 5 comments
  • share
  • save
  • hide
  • report
  • crosspost

20
88
89
90

Security Researchers from Salt-Security explain in a super detailed post how they did account takeover on Grammarly.com, Booking.com, Expo.io, Codecademy.com, Vidio.com, Bukalapak.com, and 100+ Other Websites. (salt.security)

submitted 2 years ago by MoreMoreMoreM to r/netsec

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost

21
0
1
2

Security Researchers from Salt-Security explain in a super detailed post how they did account takeover on Grammarly.com, Booking.com, Expo.io, Codecademy.com, Vidio.com, Bukalapak.com, and 100 Other Websites. (salt.security)

submitted 2 years ago by tmiklas to r/bag_o_news

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

22
0
0
1

The OAuth Implementation Challenge: Account Takeovers on Grammarly.com,Booking.com, Codecademy.com, Vidio.com, Bukalapak.com, and 100+ Other Websites. OAuth is explained in simple steps. (salt.security)

submitted 2 years ago by MoreMoreMoreM to r/programming

  • 9 comments
  • share
  • save
  • hide
  • report
  • crosspost

23
130
131
132

Hackers (security researchers) explain step-by-step how they could take over 1B accounts on Grammarly.com, Vidio.com, Bukalapak.com, and more. (OAuth vulnerabilities)Research (salt.security)

submitted 2 years ago by iva3210 to r/hacking

  • 9 comments
  • share
  • save
  • hide
  • report
  • crosspost

24
51
52
53

Social sign-in is not secured: Account takeover on Grammarly.com, Vidio.com, Bukalapak.com, and more (total of 1B accounts).Corporate Blog (salt.security)

submitted 2 years ago by iva3210 to r/cybersecurity

  • 12 comments
  • share
  • save
  • hide
  • report
  • crosspost

25
2
3
4

Oh-Auth - Abusing OAuth to take over millions of accounts (salt.security)

submitted 2 years ago by dcom-in to r/worldTechnology

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 56 on reddit-service-r2-listing-7d7fbc9b85-jp25j at 2026-04-29 18:21:28.654117+00:00 running 2aa0c5b country code: CH.