Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
2000day in Safari
Search
Bo0oM
May 21, 2019
2.3k
2
Share
2000day in Safari
Bo0oM
May 21, 2019
More Decks by Bo0oM
See All by Bo0oM
Носок на сок
bo0om
0
1.9k
Выйди и зайди нормально
bo0om
0
100
Защита от вредоносной автоматизации сегодня
bo0om
0
650
Defending against automatization using nginx
bo0om
0
900
Antibot pitch deck
bo0om
0
180
31337
bo0om
0
240
Your back is white
bo0om
0
400
FTP2RCE
bo0om
1
7.7k
Interpret it!
bo0om
0
1.2k
Featured
See All Featured
Dealing with People You Can't Stand - Big Design 2015
cassininazir
367
27k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
210
From Legacy to Launchpad: Building Startup-Ready Communities
dugsong
0
220
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
300
Testing 201, or: Great Expectations
jmmastey
46
8.2k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
Fireside Chat
paigeccino
42
3.9k
Site-Speed That Sticks
csswizardry
13
1.2k
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
0
520
jQuery: Nuts, Bolts and Bling
dougneiner
66
8.5k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
28
3.5k
16th Malabo Montpellier Forum Presentation
akademiya2063
PRO
0
140
Transcript
2000-day in Safari Anton Lopanitsyn @i_bo0om
phdays.com #PHDays XSS https://portswigger.net/web-security/cross-site-scripting
phdays.com #PHDays UXSS https://evil.com https://victim.com
phdays.com #PHDays Save as webpage, complete
phdays.com #PHDays chrome://flags
phdays.com #PHDays MHTML
phdays.com #PHDays MHTML
phdays.com #PHDays
phdays.com #PHDays Safari save as webarchive
phdays.com #PHDays Signed webarchive
phdays.com #PHDays Plaintext webarchive
phdays.com #PHDays Plaintext webarchive <script> … </script>
phdays.com #PHDays Plaintext webarchive
phdays.com #PHDays
phdays.com #PHDays https://blog.rapid7.com/2013/04/25/abusing-safaris-webarchive-file-format/
phdays.com #PHDays
phdays.com #PHDays
phdays.com #PHDays
phdays.com #PHDays
phdays.com #PHDays
phdays.com #PHDays xhtml
phdays.com #PHDays xhtml
phdays.com #PHDays file:///Users/bo0om/Library/Containers/com.apple.mail/Data/Library/Mail%20 Downloads/2F4D2013-CCBF-4341-B05E-CEB4B76F30CE/Document.xhtm file:///Users/bo0om/Downloads/33h0ygug3ulny0gvwhh3d.webarchive
phdays.com #PHDays
phdays.com #PHDays file:///Users/bo0om/Library/Containers/com.apple.mail/Data/Downloads/x.webarchive file:///Users/bo0om/Library/Containers/com.apple.mail/Downloads/x.webarchive file:///Users/bo0om/Library/Containers/Downloads/x.webarchive file:///Users/bo0om/Library/Downloads/x.webarchive file:///Users/bo0om/Downloads/x.webarchive
phdays.com #PHDays DEMO https://github.com/Bo0oM/Safari2000day)
Thank you!