Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Herrera
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
DeepSeek V4 J-Space Capability Realization-Report
(github.com)
5 points
by
Herrera
1mo ago
|
0 comments
2.
▲
Browser extensions can leak full tab URLs via a side-channel attack
(issues.chromium.org)
1 points
by
Herrera
8mo ago
|
0 comments
3.
▲
by
Herrera
2y ago
Yeah, https://xsleaks.dev tracks most of the known ways to leak cross-origin data.
4.
▲
AppCache's Forgotten Tales
(blog.lbherrera.me)
3 points
by
Herrera
5y ago
|
0 comments
5.
▲
Write-up for h1415’s CTF challenge
(lbherrera.github.io)
1 points
by
Herrera
7y ago
|
0 comments
6.
▲
by
Herrera
7y ago
Bleichenbacher'06 never dies.
7.
▲
XS-Searching Google’s bug tracker to find out vulnerable source code
(medium.com)
36 points
by
Herrera
8y ago
|
0 comments
8.
▲
XS-Searching Google’s bug tracker to find out vulnerable source code
(medium.com)
2 points
by
Herrera
8y ago
|
0 comments
9.
▲
by
Herrera
8y ago
Interesting... I reported a variation of this issue to Google back in 2015 and they said they weren't "concerned about the premise of the attack in the bug description. You can always make the back button go to a page under your c
10.
▲
Reverse Engineering an Integrated Circuit for Pwn2Win 2017 CTF
(blog.dragonsector.pl)
3 points
by
Herrera
9y ago
|
0 comments
11.
▲
by
Herrera
10y ago
I was playing with picture-in-picture attacks on Chrome some time ago and even proposed a way for mitigation, but it was dismissed. Here's the PoC I did: https://www.youtube.com/watch?v=0oega6C5SF0 And the mitigation I
12.
▲
Dirty COW (CVE-2016-5195) – Linux Kernel Privilege Escalation Vulnerability
(github.com)
2 points
by
Herrera
10y ago
|
0 comments
13.
▲
An early history of the internet and hacking, by Matty Angel
(quietlydreaming.wumpy.xyz)
2 points
by
Herrera
10y ago
|
0 comments
14.
▲
by
Herrera
10y ago
Really? That is strange, because there is ways this could be exploited... Can you link them to me?
15.
▲
by
Herrera
10y ago
A somewhat related topic: A few months ago Google fixed a vulnerability on the inline installation. It was possible to start a install on the attacker's website and then redirect the page to an arbitrary one. This would confuse the use
16.
▲
by
Herrera
11y ago
If you keep your left mouse button pressed you can cheat too.
17.
▲
by
Herrera
11y ago
You are right. You receive one image containing a inspirational message for your family and decide to send to your family members. Then it changes to a image asking for money to be sent to an account because you are in need. I could see thi
18.
▲
by
Herrera
11y ago
Yes, if you invest at least $1,000,000 and employ more than 10 people for two years you will be eligible to the EB-5 visa. It seems a good way to get a green card if you have the money.
19.
▲
by
Herrera
11y ago
Thank you! I got involved with the security world recently and I'm really enjoying it. And I would like to clarify myself, the comment I made earlier was a little ambiguous. The bug that got fixed only spoofs the omnibox and not the HT
20.
▲
by
Herrera
11y ago
I already did report them. The first one was fixed (CVE-2015-6782), got $1k from Google. There are three more they are working on.
21.
▲
by
Herrera
11y ago
It is not always enough. For example, recently I have found several ways to spoof the URL and HTTPS lock on Google Chrome. So phishing seems to be a concern.