Uncategorized

[BugBounty] malicious redirect on mailroom.prezi.com

Dear readers, today i want to share a short story of a bug i found on one of prezi’s subdomains called mailroom.prezi.com.The Webserver at http://mailroom.prezi.com is configured to redirect the Users to the Login Page of Prezi, so far so good, i found out that if you add a Domain lets say http://mailroom.prezi.com/.anydomain.com to the end

[BugBounty] malicious redirect on mailroom.prezi.com Read More »

Google Chrome Security: Multiple leading slashes in URLs may confuse some server-side XSS filters

Today i  reported a strange bug to the devs of the Chromium Project, look at the following lines of code : <html> <script src=http:\\\\\\\\\\\\monitor.it-securityguard.com\\\\\\\\\\\\\test.js> </script> </html>   You see those leading slashes ? Do you think that this is an valid URL a Browser would process ? In fact it does not look like a valid

Google Chrome Security: Multiple leading slashes in URLs may confuse some server-side XSS filters Read More »

en_USEnglish