
XSS— TryHackMe Part of my Cyber Security Internship at Cyber Leelawat Cross-site scripting (XSS) remains one of the common vulnerabilities that threaten web applications to this day. Cross-Site …
Nguồn: https://medium.com/@darshmohile303/xss-tryhackme-62be47977a8c. 8sync News chỉ tóm tắt và dẫn link; bản quyền nội dung thuộc tác giả và nguồn gốc.
Đọc tin ở đây, luyện code, học theo lộ trình và luyện IELTS trên các sản phẩm anh em — tất cả kết nối với nhau trong hệ sinh thái 8 Sync Dev.
Cổng chính của hệ sinh thái: giới thiệu sản phẩm, blog và bảng giá trọn bộ.
Khám pháHọc theo lộ trình rõ từng chặng: video, quiz chấm tự động, certificate và mentor đang làm nghề.
Xem lộ trìnhHơn 600 bài FREE, đề tiếng Việt, chấm tự động 7 ngôn ngữ — chạy ngay trên trình duyệt.
Bản cập nhật mới của Content Filter từ ManagedMethods bổ sung nhiều tính năng dựa trên phản hồi khách hàng, như giám sát mở rộng cho các nền tảng AI/LLM (Perplexity, Grok, DeepSeek, MagicSchool AI), chế độ SafeSearch cấp trình duyệt, chặn wildcard TLD, chính sách lọc theo thời gian, kiểm soát quản trị theo vai trò, kế thừa chính sách nhóm, nhập khẩu hàng loạt từ YouTube/keyword, và báo cáo vi phạm cải tiến với phản hồi false-positive để tinh chỉnh mô hình ML. Ngoài ra còn có chatbot hỗ trợ trong ứng dụng và tuân thủ WCAG 2.1.
Lập trình viên nên đọc bài này để hiểu cách tích hợp và tối ưu hóa các giải pháp bảo vệ nội dung trong môi trường giáo dục K-12, đặc biệt là khi cần xây dựng hệ thống quản lý nội dung an toàn, tuân thủ tiêu chuẩn và hỗ trợ tính năng AI/ML trong ứng dụng của mình.

LWN.net provides an update on the ongoing AI scraper bot problem that has worsened since early 2025. Scraper attacks now originate predominantly from residential and mobile proxy networks — some criminal botnets, others semi-legitimate services like Bright Data that pay app developers to route traffic through users' devices. Google and the FBI recently took down a residential proxy network called NetNut, providing temporary relief. LWN describes its own defensive measures in general terms: aggressive site optimization and minimizing expensive operations under attack, while deliberately avoiding tools like Anubis (proof-of-work) and avoiding whitelisting dominant search engines. The piece argues that the entire open web is under threat, with scrapers imposing a heavy tax on site operators and users alike, and calls for the industry to be held to minimal ethical standards. Comments discuss Common Crawl as a cooperative alternative, the difficulty of policing app stores, and a proposal for privacy-preserving zero-knowledge proof-of-humanity protocols using zkVMs and remote attestation.
A detailed bug bounty writeup describing a four-vulnerability chain that achieves one-click account takeover. The chain combines: (1) a DOM XSS sink in a React error page that passes an unvalidated backURL query parameter to window.location.assign; (2) an Akamai WAF bypass using bracket-notation property access (top["setTimeout"]) to avoid keyword-paren adjacency detection; (3) window.name cross-origin smuggling to deliver the payload without it ever appearing in the inspected URL; and (4) abuse of a first-party authentication SDK that exposes methods returning signed JWTs and live AWS STS credentials to any executing JavaScript. The result: nine webhook hits in 8 seconds, yielding full session metadata, a signed RS256 JWT containing PII, and temporary credentials for two separate AWS accounts. Key takeaways include modeling WAF rules structurally rather than brute-forcing variants, the persistent cross-origin nature of window.name, and how global auth SDKs dramatically escalate XSS severity beyond simple cookie theft.
A thorough breakdown of Cross-Site Request Forgery (CSRF) attacks covering the core mechanics (automatic cookie attachment), two real-world exploits from 2008 (router DNS hijack and uTorrent configuration abuse), and a manual testing procedure for developers. Defences covered include synchronizer tokens, signed double-submit cookies, and SameSite cookie attributes with a clear explanation of what each value (Strict, Lax, None) does and doesn't protect against. The guide also addresses login CSRF, the CSRF vs XSS distinction, and common misconceptions like HTTPS or referrer headers being sufficient defences.
Troy Hunt and Scott Helme have launched 'Why no Passkeys?', a site inspired by their 8-year-old 'Why no HTTPS?' project that publicly tracked websites failing to implement HTTPS. The new site aims to similarly shame companies that haven't adopted passkeys, encouraging community pressure by country. Scott built the project largely solo using Claude Code, following Troy's original intent after a phishing incident prompted him to register the domain.
Mozilla proposes PACT (Private Access Control Tokens), a new web standard to replace CAPTCHAs and invasive bot-detection with privacy-preserving rate limiting. The system uses three roles: Anchors (entities that vouch for users via scarce signals like subscriptions or phone numbers), Moderators (rate-limit enforcers), and Credentials (stateful cryptographic tokens). Built on Privacy Pass and Anonymous Credit Tokens, PACT uses issuer blinding and zero-knowledge proofs so sites only learn whether a user is within a rate limit — nothing more. Unlike Google's Web Environment Integrity or Apple's Private Access Tokens, PACT avoids tying web access to specific hardware vendors. Mozilla plans to bring draft specs to IETF and W3C, with Cloudflare and Chrome already involved.
A ten-year retrospective crawl of the Tranco Top 1 Million websites measuring web security adoption as of June 2026. Key findings: HTTPS redirects now cover 658,038 sites (up from 62,043 in 2015), CSP has grown 12,360% over the decade but nearly half of all policies still contain unsafe-inline or unsafe-eval. HSTS is on 252,846 sites but only 21% are preload-eligible. Referrer-Policy tripled since 2022. New metrics this year include cookie security attributes, DMARC/SPF records, and cross-origin isolation headers (COOP/COEP). Cloudflare fronts over a third of responding sites, heavily skewing aggregate metrics. Over half the web still scores an F on security headers, though the F count dropped by ~124,000 since 2022. Part two will cover TLS, certificate lifetimes, and post-quantum cryptography.