RSSAmplifier

Blog

Slonser Notes

Recent content on Slonser Notes

blog.slonser.infoRSS feed ↗10 posts

Latest posts

Never Trust the Output: Data Pollution in AI Agents and MCP

Disclaimer: This article is intended for educational purposes and security specialists conducting authorized testing. The author assumes no responsibility for any misuse of the information provided. Distribution of malicious software, system disruption, and privacy violations are punishable by law. Introduction I’m sure most of you are already familiar with the concept of Prompt Injection…

Make Self-XSS Great Again

Disclaimer: This article is intended for security professionals conducting authorized testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction Many security…

Why Protocol Matters: Evil PWA Attack on Casdoor

The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction In this article, I would…

DOM Purify - dirty namespace bypass

The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction In this article, I want…

Old new email attacks

The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction This article will be…

Exploring IPv6 Zone Identifier

Introduction This article is dedicated to a series of tricks utilizing the modern capabilities of IPv6 and the shortcomings of address parser implementations in standard libraries of popular programming languages. IPv6 Zone I think many people have an idea of what IPv6 and IPv4 addresses look like: 2001:0db8:85a3:0000:0000:8a2e:0370:7334 - IPv6 192.168.0.1 - IPv4 When including an IPv6 address in…

MySQL2: Dangers of User-Defined Database Connections

The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction The node-mysql2 library…

DOM Purify - untrusted Node bypass

The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Introduction In this article, I aim…

CVE-2023-5480: Chrome new XSS Vector

Chrome XSS The article is informative and intended for security specialists conducting testing within the scope of a contract. The author is not responsible for any damage caused by the application of the provided information. The distribution of malicious programs, disruption of system operation, and violation of the confidentiality of correspondence are pursued by law. Preface This article is…

Who Am I

Slonser. I am Vsevolod Kokorin (Slonser), security researcher at Solidlab, C4T BuT S4D CTF team player. You can contact with me at Telegram.