🦞🌯 Lobster Roll

Thread

Hacking the JavaScript Lottery (medium.com)

Stories related to "Hacking the JavaScript Lottery" across the full archive.

Stuffing Javascript into DNS names (skullsecurity.org)
Rowhammer.js: A Remote Software-Induced Fault Attack in JavaScript (arxiv.org)
Backdooring your JavaScript using minifier bugs (zyan.scripts.mit.edu)
Hacking the JavaScript Lottery (medium.com)
Local network scanner in javascript (blog.skylined.nl)
[tor-talk] Javascript exploit (lists.torproject.org)
Scary shit (if you're on Windows, which is already scary in its own right)
ADsafe - Making JavaScript Safe for Advertising (adsafe.org)
Many claim they don't run ads due to security risk. This is one of CompSci's interesting approaches to reducing it. Worth review for weaknesses or experiments on usability.
New ASLR-busting JavaScript is about to make drive-by exploits much nastier (arstechnica.com)
52% of all JavaScript npm packages could have been hacked via weak credentials (bleepingcomputer.com)
JavaScript Coinhive in Excel (charles.dardaman.com)
Microsoft recently announced that JavaScript would be enabled in Excel, resulting in this proof of concept.
Undetectable Remote Arbitrary Code Execution Attacks through JavaScript and HTTP headers trickery (bugzilla.mozilla.org)
A timing attack with CSS selectors and Javascript (blog.sheddow.xyz)
AWS takeover through SSRF in JavaScript (10degres.net)
Protecting your JavaScript APIs (medium.com)
Compile Your Own Type Confusions: Exploiting Logic Bugs in JavaScript JIT Engines (phrack.org)
JavaScript Template Attacks (ndss-symposium.org)
Introducing Osgood: A secure, fast, and simple platform for running JavaScript HTTP servers (dev.to)
Sodium-Plus: A Positive Cryptography Experience for JavaScript Developers (dev.to)
Improving the Cryptography of the JavaScript Ecosystem (paragonie.com)
Message Encryption in JavaScript and PHP with Libsodium (dev.to)
JavaScript Libraries Are Almost Never Updated Once Installed (blog.cloudflare.com)
taviso/avscript: Avast JavaScript Interactive Shell (github.com)
How To Bypass CSP By Hiding JavaScript In A PNG Image (secjuice.com)
Spectre Strikes Back: New Hacking Vulnerability Affecting Billions of Computers Worldwide (scitechdaily.com)
Computing experts thought they had developed adequate security patches after the major worldwide Spectre flaw of 2018, but UVA’s discovery shows processors are open to hackers again. In 2018, industry and academic researchers revealed a potentially devastating hardware flaw that made computers...
How JavaScript Restrictor prevents other parties from sniffing on your local applications (polcak.github.io)
Reasons to avoid Javascript CDNs (blog.wesleyac.com)
Javascript Destructing and Untrusted Data (petecorey.com)
How to create a Secure, Random Password with JavaScript (blog.hboeck.de)
A thought on JavaScript "proof of work" anti-scraper systems (utcc.utoronto.ca)
Object-capability Programming in Javascript (youtube.com)