⤷ Title: WebGPU: Hacking 101
════════════════════════
𐀪 Author: Pratik Sharma
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 20:49:13 GMT
════════════════════════
⌗ Tags: #javascript #programming #security #hacking
════════════════════════
𐀪 Author: Pratik Sharma
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 20:49:13 GMT
════════════════════════
⌗ Tags: #javascript #programming #security #hacking
Medium
WebGPU: Hacking 101
WebGPU Gives Websites Access to Your GPU. So Why Can’t a Page Read Your VRAM?
⤷ Title: DOM XSS using web messages
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
Medium
DOM XSS using web messages
Exploiting an Unchecked postMessage Listener — DOM XSS Using Web Messages (PortSwigger Academy)
⤷ Title: How a JavaScript file led me to an Admin Access
════════════════════════
𐀪 Author: Said-Abbosxon Nabijonov | 0trc
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 09:05:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #infosec #pentesting #javascript
════════════════════════
𐀪 Author: Said-Abbosxon Nabijonov | 0trc
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 09:05:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #infosec #pentesting #javascript
Medium
How a JavaScript file led to an Admin Access
During a pentest I found a JavaScript file that led to me an API with exposed Swagger. Once account creation later I was an Admin.
Forwarded from Bug Bounty Diary
✎ Extract & Download All JavaScript Files for Recon
For modern web apps, scraping
My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
For modern web apps, scraping
<script> tags or relying on Burp's Site Map often isn't enough. Why? Because applications may dynamically load JavaScript from CDNs, cross-origin domains, specific routes (Lazy Loading), or after user interactions.My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from
.HAR file using unhar (I'll talk about it in the next post.)#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
❤1
Forwarded from Bug Bounty Diary
✎ Unhar - Extract, Unminify, Beautify Javascript files from .Har file
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
unhar turns a raw
In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
● Usage
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a
.HAR file for further local analysis. Now, let’s take it a step further with unhar and process that HAR files. unhar turns a raw
.HAR file into a structured set of web assets for local analysis. It extracts unique JavaScript and HTML resources while preserving the original URL structure, fetches available source maps, beautifies/unminifies JavaScript, and extracts inline scripts from HTML pages.In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis
● Installation
git clone https://github.com/Spix0r/unhar
cd unhar
● Usage
# custom output directory
python3 unhar.py site.har --output folder
# skip source map fetching
python3 unhar.py site.har --no-srcmap
# skip beautify
python3 unhar.py site.har --no-beautify
• Repository: Github
#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
⤷ Title: JAVA SCRIPT DEOBFUSCATION
════════════════════════
𐀪 Author: Hassan Saif
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 16:33:55 GMT
════════════════════════
⌗ Tags: #js_deobfuscation_walk_thr #hackthebox_writeup #js_deobfuscation #javascript #hackthebox
════════════════════════
𐀪 Author: Hassan Saif
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 16:33:55 GMT
════════════════════════
⌗ Tags: #js_deobfuscation_walk_thr #hackthebox_writeup #js_deobfuscation #javascript #hackthebox
Medium
MODULE 06 — JAVA SCRIPT DEOBFUSCATION
MODULE 06 — JAVA SCRIPT DEOBFUSCATION To access the lab visit the following link: https://academy.hackthebox.com/app/module/41 Obfuscation …
⤷ Title: Systematic JavaScript Reconnaissance
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 14:54:34 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #infosec #reconnaissance #cybersecurity
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 14:54:34 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #infosec #reconnaissance #cybersecurity
Medium
Systematic JavaScript Reconnaissance
JavaScript surely knows too much.
⤷ Title: JavaScript: Simple Demo — Try Hack Me
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 07:13:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #javascript_simple_demo #pre_security #tryhackme
════════════════════════
𐀪 Author: Chittanoori Divyashrith
════════════════════════
ⴵ Time: Fri, 04 Sep 2026 07:13:23 GMT
════════════════════════
⌗ Tags: #cybersecurity #javascript_simple_demo #pre_security #tryhackme
Medium
JavaScript: Simple Demo — Try Hack Me
Task 1 — Introduction
⤷ Title: Finding Secrets Inside JavaScript Files
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Sat, 05 Sep 2026 22:53:39 GMT
════════════════════════
⌗ Tags: #javascript #cybersecurity #ethical_hacking #bug_bounty #technology
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Sat, 05 Sep 2026 22:53:39 GMT
════════════════════════
⌗ Tags: #javascript #cybersecurity #ethical_hacking #bug_bounty #technology
Medium
Finding Secrets Inside JavaScript Files
Learn how I analyze JavaScript files during reconnaissance to uncover API endpoints, secrets, and other valuable information for bug bounty…
⤷ Title: Cloudflare Raises Workers Size Limit to 64 MiB for Free and Paid Plans
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 03:46:37 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Workers #developer platform #Edge Computing #JavaScript bundle #serverless #Workers size limit #Wrangler
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 03:46:37 +0000
════════════════════════
⌗ Tags: #Technology #cloudflare #Cloudflare Workers #developer platform #Edge Computing #JavaScript bundle #serverless #Workers size limit #Wrangler
Daily CyberSecurity
Cloudflare Raises Workers Size Limit to 64 MiB for Free and Paid Plans
According to the changelog published by Cloudflare, from today both the free and paid Workers subscription plans support uncompressed code bundles of up to 64 MiB. Previously, Workers judged wheth…
⤷ Title: Common Sensitive Files You Should Look For During Web Recon
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
════════════════════════
𐀪 Author: Monika
════════════════════════
ⴵ Time: Mon, 07 Sep 2026 19:17:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #javascript #technology #hacking
Medium
Common Sensitive Files You Should Look For During Web Recon
A beginner-friendly guide to finding publicly accessible files that can reveal valuable information during bug bounty reconnaissance.
⤷ Title: A Browser-Visible API Key Is Evidence, Not a Verdict
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
════════════════════════
𐀪 Author: Lars at Veristria
════════════════════════
ⴵ Time: Tue, 08 Sep 2026 10:32:33 GMT
════════════════════════
⌗ Tags: #javascript #incident_response #cybersecurity #api_security #devsecops
Medium
A Browser-Visible API Key Is Evidence, Not a Verdict
How to separate intended public identifiers from real client-side secret exposure
⤷ Title: When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
════════════════════════
𐀪 Author: Fatima Zakir
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 22:04:20 GMT
════════════════════════
⌗ Tags: #javascript #vulnerability #technology #hacking #cybersecurity
Medium
When JavaScript Gets Confused: A Look at Chrome’s V8 Vulnerabilities
Let’s talk about CVE-2026–85046
⤷ Title: vm2’s Sandbox Just Failed for the Third Time This Week.
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
════════════════════════
𐀪 Author: Vortex 404
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:51:47 GMT
════════════════════════
⌗ Tags: #devsecops #vulnerability_management #nodejs #javascript #application_security
Medium
vm2’s Sandbox Just Failed for the Third Time This Week. A Million Weekly Downloads Are Still Running It
Three separate CVSS 10.0 sandbox escapes landed days apart — in a library that was declared dead once already
⤷ Title: I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
════════════════════════
𐀪 Author: Mr Abdullah
════════════════════════
ⴵ Time: Wed, 23 Sep 2026 07:47:00 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #javascript #penetration_testing #bug_bounty #xss_attack
Medium
I Found an Unauthenticated XSS in a WordPress Hotel Plugin — Then Someone Beat Me to It by a Week
A reflected XSS in nd-booking, a display:none trap that fools most PoCs, and an honest look at what “duplicate” really means in bug bounty.
⤷ Title: Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
════════════════════════
𐀪 Author: Bhanvararam choudhary
════════════════════════
ⴵ Time: Thu, 24 Sep 2026 14:14:59 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #cybersecurity #prototype_pollution #web_security
Medium
Mastering Prototype Pollution: A Complete Walkthrough of PortSwigger Labs
From Client-Side DOM XSS to Server-Side RCE and Data Exfiltration — A deep dive into sources, gadgets, sinks, and bypassing flawed…
⤷ Title: Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
════════════════════════
𐀪 Author: Affanhaxor
════════════════════════
ⴵ Time: Tue, 29 Sep 2026 05:41:56 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #javascript #bug_bounty #ctf
Medium
Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption
Introduction
⤷ Title: Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 04:10:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_102673 #CVE_2026_102674 #CVE_2026_102676 #desktop app security #Electron #Electron vulnerabilities #javascript #Sandbox Bypass
Daily CyberSecurity
Electron Fixes Five High-Severity Sandbox and Isolation Vulnerabilities
TL;DR Electron maintainers published five Electron vulnerabilities on September 29, 2026, all rated High, with CVSS scores from 7.4 to 8.3. Each flaw lets untrusted content escape a sandbox, an or…
⤷ Title: Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
════════════════════════
𐀪 Author: Lokesh Kumar
════════════════════════
ⴵ Time: Wed, 30 Sep 2026 10:19:22 GMT
════════════════════════
⌗ Tags: #javascript #ethical_hacking #youtube
Medium
Moving YouTube Subscriptions Using Only the Browser Console and Poor Judgment
Reading time: 4 minutes. Regret time: ongoing.
⤷ Title: Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
Medium
Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
Java RMI (Remote Method Invocation) is a way for one Java application to ask another Java application on a different machine to perform a…