writeups.xyz writeups.xyz / Frans Rosén (@Fransrosen)

Title Vulnerabilities Programs Authors
Account hijacking using "dirty dancing" in sign-in OAuth-flows
Security issues with cloudflare/odoh-server-go and the ODoH RFC draft
Hacking CloudKit - How I accidentally deleted your Apple Shortcuts
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token