Media Summary: Episode 8: In this episode of Critical Thinking - Bug Bounty Podcast we drop some critical bugs which leak raw credit card info. In this episode, we dive into one of the most ignored client-side vulnerability classes: Hello Due to the interest in my film "window.

Fixed Xss Via Postmessage On - Detailed Analysis & Overview

Episode 8: In this episode of Critical Thinking - Bug Bounty Podcast we drop some critical bugs which leak raw credit card info. In this episode, we dive into one of the most ignored client-side vulnerability classes: Hello Due to the interest in my film "window. Disclaimer This video is intended strictly for educational purposes. All techniques demonstrated should be used responsibly and ... René de Sain – renniepak - NahamCon 2025 Link to the slides: NOTE: rs0n is no longer actively bug hunting. Any future content on this channel will be focused on defensive Application Security ...

Photo Gallery

[Fixed] XSS via postmessage on zoho workdrive webapp
Fixed postMessage XSS on okx.com
PostMessage Exploits and CSS Injection (Ep. 8)
I Stole Session Cookies with postMessage DOM XSS
Discovering DOM-Based XSS on DeepSeek.com via postMessage Exploitation
A Quick Introduction to postMessage XSS
Postmessage XSS?! Solution to September '22 XSS Challenge
Client Side 01: postMessage Bugs
XSS window.postMessage + english subtitles
Stored xss via File Upload Leads to $3000 Bounty #bug #bugbounty #xss #fileupload #hackwithsuryesh
Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks
Bug Bounty Hunting | Methodology to Bypass Security Controls & Exploit XSS on Real World Targets
View Detailed Profile
[Fixed] XSS via postmessage on zoho workdrive webapp

[Fixed] XSS via postmessage on zoho workdrive webapp

It's possible for an attacker to achieve

Fixed postMessage XSS on okx.com

Fixed postMessage XSS on okx.com

Generic

PostMessage Exploits and CSS Injection (Ep. 8)

PostMessage Exploits and CSS Injection (Ep. 8)

Episode 8: In this episode of Critical Thinking - Bug Bounty Podcast we drop some critical bugs which leak raw credit card info.

I Stole Session Cookies with postMessage DOM XSS

I Stole Session Cookies with postMessage DOM XSS

I found a

Discovering DOM-Based XSS on DeepSeek.com via postMessage Exploitation

Discovering DOM-Based XSS on DeepSeek.com via postMessage Exploitation

While testing https://chat.deepseek.com, I found a DOM

A Quick Introduction to postMessage XSS

A Quick Introduction to postMessage XSS

Join us as we dive into the world of

Postmessage XSS?! Solution to September '22 XSS Challenge

Postmessage XSS?! Solution to September '22 XSS Challenge

... a

Client Side 01: postMessage Bugs

Client Side 01: postMessage Bugs

In this episode, we dive into one of the most ignored client-side vulnerability classes:

XSS window.postMessage + english subtitles

XSS window.postMessage + english subtitles

Hello Due to the interest in my film "window.

Stored xss via File Upload Leads to $3000 Bounty #bug #bugbounty #xss #fileupload #hackwithsuryesh

Stored xss via File Upload Leads to $3000 Bounty #bug #bugbounty #xss #fileupload #hackwithsuryesh

Disclaimer This video is intended strictly for educational purposes. All techniques demonstrated should be used responsibly and ...

Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks

Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks

René de Sain – renniepak - NahamCon 2025 Link to the slides: https://0-a.nl/nahamcon/

Bug Bounty Hunting | Methodology to Bypass Security Controls & Exploit XSS on Real World Targets

Bug Bounty Hunting | Methodology to Bypass Security Controls & Exploit XSS on Real World Targets

NOTE: rs0n is no longer actively bug hunting. Any future content on this channel will be focused on defensive Application Security ...

YouTube.com postMessage Cross-Site Scripting Example

YouTube.com postMessage Cross-Site Scripting Example

The following video demonstrates a