Chackal (Esdras DAGO)
banner
0xchackal.bsky.social
Chackal (Esdras DAGO)
@0xchackal.bsky.social
"Vulnerability researcher" doing BB on free time (http://yeswehack.com/hunters/chackal) Also doing some Reverse on many targets but find no vuln 😒


Blogpost: https://medium.com/@chackal
Reposted by Chackal (Esdras DAGO)
Last year, I had a few weeks between jobs and decided to look at the infrastructure security of random Linux distributions with the good friends at Fenrisk.

We ended up getting code execution on the Fedora Git forge hosting all package sources and on the Open Build Service instance of openSUSE […]
Original post on infosec.exchange
infosec.exchange
March 19, 2025 at 11:10 AM
Reposted by Chackal (Esdras DAGO)
I'm very happy to finally share the second part of my DOMPurify security research 🔥

This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)!

Link 👇
mizu.re/post/explori...

1/2
February 10, 2025 at 5:57 PM