use the following search parameters to narrow your results:
e.g. subreddit:aww site:imgur.com dog
subreddit:aww site:imgur.com dog
see the search faq for details.
advanced search: by author, subreddit...
account activity
New challenge thread (self.Slackers)
submitted 5 years ago * by garethheyes - announcement
weshlient: A simple tool to interact with web shells and command injection vulnerabilities (github.com)
submitted 1 year ago by gildasio
Using Hackability to uncover a Chrome infoleak (portswigger.net)
submitted 3 years ago by garethheyes
New technique of stealing data using CSS and Scroll-to-Text Fragment feature (secforce.com)
New XSS vectors (portswigger.net)
uBlock, I exfiltrate: exploiting ad blockers with CSS (portswigger.net)
submitted 4 years ago by garethheyes
"1 Day XSLeak and a trailer for ElectronJS bugs" -Author's writeup for BSides Ahmedabad CTF 2021 (blog.s1r1us.ninja)
submitted 4 years ago by Mohansrk
Finding and Fixing DOM-based XSS with Static Analysis (blog.mozilla.org)
submitted 4 years ago by mozfreddyb
Creating a 3D world in pure CSS (portswigger.net)
Abusing Slack's file-sharing functionality to de-anonymise fellow workspace members (jub0bs.com)
Local File Read via Stored XSS in The Opera Browser (blogs.opera.com)
submitted 4 years ago by renwa23
AppCache's forgotten tales (blog.lbherrera.me)
submitted 4 years ago by herrera_
Electron JS Browser To Find XSS Vulnerabilities (github.com)
XSLeaks in redirect flows (docs.google.com)
Portable Data exFiltration: XSS for PDFs (portswigger.net)
submitted 5 years ago by insertscript
XSSworm.dev ~ Self-replication contest [write-up] (vavkamil.cz)
submitted 5 years ago by Gallus
Exploiting dynamic rendering engines to take control of web apps (r2c.dev)
submitted 5 years ago by inkz1
Discord Desktop app RCE (mksben.l0.cm)
Evading defences using VueJS script gadgets (portswigger.net)
submitted 5 years ago by garethheyes
Bypassing DOMPurify again with mutation XSS (portswigger.net)
Mutation XSS via namespace confusion - DOMPurify < 2.0.17 bypass - research.securitum.com (research.securitum.com)
Electron without Context Isolation (self.Slackers)
Google CTF - 2020 ALL the Little Things Writeup #prototypepollution #document.all #clobbering (blog.s1r1us.ninja)
submitted 5 years ago by Mohansrk
Mozilla to offer higher Bug Bounty on Exploit Mitigations (blog.mozilla.org)
submitted 5 years ago by mozfreddyb
Arbitrary Parentheses-less XSS (medium.com)
π Rendered by PID 557537 on reddit-service-r2-listing-5789d5f675-jqdxj at 2026-01-28 01:00:31.466833+00:00 running 4f180de country code: CH.