Again just a quick JS PoC (nothing new, just some PoC to try it):
JS Array length of 4294967295, and push vs [][length]=value behavior. Push fails, assignment works but length value isn't increased anymore. Don't really see how this can be abused.
insert-script.com/examples/javas…
Quick browser documentation PoCs (nothing new, just some PoCs to try it):
Postmessage with null origin and null source- insert-script.com/examples/ifram…
Authorization header and redirects - relevant for client side path traversal insert-script.com/examples/redir…
Cross-Site ETag Length Leak
blog.arkark.dev/2025/12/26/eta…
I just posted the author writeup for impossible-leak in SECCON CTF 14 Quals. As far as I know, this is a new XS-Leak technique! The ETag header can become a side channel :)
Not only a really interesting chain of bugs - but IMO it shows how LLMs can help at certain parts during an assessment. I can't wait to use it myself. Keep up your good work :-)
We believe AI accelerates cyber attacks by closing the knowledge gap faster.
We used Hacktron CLI to prove it - compressing weeks of research into days.
Read more about it here:
hacktron.ai/blog/supapwn