Mathias Karlsson

BountyDash – A local bug bounty statistics dashboard

BountyDash was created by @fransrosen and @avlidienbrunn to create a better overview of your bug bounty rewards. By tagging all your reports in the tool you’re also able to categorize all vulnerability types, plotting up a graph around your activity cross platforms and get forecasts around your future findings. Everything runs locally and there are import scripts you can run to fetch the data from each platform.

Login/logout CSRF: Time to reconsider?

My stance on login/logout CSRF has changed. I, like many others, used to quickly dismiss them as a non-security issue. However, there are several situations where they could become a security issue.

CSP flaws: cookie fixation

TL;DR: CSP can’t block <meta http-equiv="Set-Cookie" content="a=b">. XSS vulnerability on a page with CSP can still be source for attacks that are based on writing cookies. Let’s take a look at some examples of cookie fixation issues.

The pitfalls of postMessage

The postMessage API is an alternative to JSONP, XHR with CORS headers and other methods enabling sending data between origins. It was introduced with HTML5 and like many other cross-document features it can be a source of client-side vulnerabilities.