Shazzer had an interesting bug. I write to a blob URL thats sandboxed but because its a blob URL it breaks relative URLs which means vectors with them would return false negatives. The fix was: use a base tag to change the domain. This fixes vectors like:
gaz@infosec.exchange
@gaz@infosec.exchange
Posts
-
Shazzer had an interesting bug. -
@gaz Have you seen this?@freddy Yeah it used JS for some aspects but still cool. I think we're not far from doing it in CSS/HTML only
-
@gaz Have you seen this?@freddy So cool!!!