Episode 79: In this episode of Critical Thinking - Bug Bounty Podcast we deepdive CSS injection, and explore topics like sequential import chaining, font ligatures, and attribute exfiltration.
Follow us on twitter at: / ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: [email protected]
Shoutout to / realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater & Teknogeek on twitter:
/ 0xteknogeek
/ rhynorater
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at https://ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Resources:
SpaceRaccoon's Universal Code Execution Extensions
https://spaceraccoon.dev/universal-co...
Escalating Client Side Path Traversal
https://x.com/isira_adithya/status/18...
Full-time Bug Bounty Blueprint:
https://www.criticalthinkingpodcast.i...
Sequential Import Chaining
/ better-exfiltration-via-html-injection
CSS Exfiltation
https://github.com/PortSwigger/css-ex...
Link that Justin was talking about
https://github.com/PortSwigger/css-ex...
Font Ligatures
https://x.com/kinugawamasato/status/1...
Lava Dome bypass
https://github.com/LavaMoat/LavaDome/...
Stealing Data in Great style
https://research.securitum.com/steali...
Steal Script Contents
https://github.com/PortSwigger/css-ex...
Masato Kinugawa’s Tweet
https://x.com/kinugawamasato/status/1...
CSS Injection: Attacking with Just CSS
https://aszx87410.github.io/beyond-xs...
CSS Injection Primitives
https://x-c3ll.github.io/posts/CSS-In...
Timestamps:
(00:00:00) Introduction
(00:02:32) Universal Code Execution
(00:11:32) Escalating Client Side Path Traversal
(00:16:56) Justin's Defcon talk & Bug Bounty Blueprint
(00:23:32) CSS Injection
(00:39:23) Font Ligatures
(00:54:30) Descent Override and display:block
(01:02:10) Some Final Research