web-socket-security

1 article
sort: new top best
clear filter
0 7/10

Security researcher discovered a $12,000 intersection of three vulnerabilities in a bitcoin gambling website's chat system: a denial-of-service flaw via malformed URLs that crash the JavaScript client ($2,000), combined with XSS through an unvalidated external redirect endpoint and clickjacking via iframe embedding that enables session hijacking ($10,000). The researcher exploited URL encoding edge cases and double-slash bypass techniques to achieve code execution within application context.

bustabit.com Sam Curry Samy Kamkar aquatone dirsearch RFC 2396
samcurry.net · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details