Open in app

Sign in

Write

Sign in

Daniel Santos
Daniel Santos

125 Followers

Home

About

Pinned

From SVG and back, yet another mutation XSS via namespace confusion for DOMPurify < 2.2.2 bypass

For those who are only interested in the final payload here you go (I won’t judge). For the ones interested in why it works, please bear…

Nov 11, 2020
nested forms parsed twice
nested forms parsed twice
Nov 11, 2020

Reversing a Magento RCE (CVE-2022–24086)

NOTE: This post has been sitting on my drafts forever and I don’t remember why I never published it before 🤣. The vulnerability addressed…

Jun 27, 2024
Reversing a Magento RCE (CVE-2022–24086)
Reversing a Magento RCE (CVE-2022–24086)
Jun 27, 2024

.NET Threadless Process Injection

Disclaimers

Feb 18, 2024
.NET Threadless Process Injection
.NET Threadless Process Injection
Feb 18, 2024

Leaking Microsoft Defender’s exclusions using a timing oracle

Around January 2022, the fact that unprivileged users were able to enumerate Microsoft Defender’s exclusion rules gained notoriety. A…

Feb 11, 2024
Leaking Microsoft Defender’s exclusions using a timing oracle
Leaking Microsoft Defender’s exclusions using a timing oracle
Feb 11, 2024

Capturing the flag with ChatGPT: solving DiceCTF 2023 rev/time-travel

I was recently invited to play the latest edition of DiceCTF. It was a last-minute invite, so I just played the last two hours of the…

Feb 7, 2023
Capturing the flag with ChatGPT: solving DiceCTF 2023 rev/time-travel
Capturing the flag with ChatGPT: solving DiceCTF 2023 rev/time-travel
Feb 7, 2023

Bypassing Defender’s self-protect mechanism

I recently started working as a Red Team lead, and figuring out ways to bypass antivirus engines became a regular thing. I am a huge fan of…

Feb 17, 2022
Bypassing Defender’s self-protect mechanism
Bypassing Defender’s self-protect mechanism
Feb 17, 2022
Techiepedia

Published in

Techiepedia

The tale of CVE-2021–34479 (VSCode XSS)

This April, I finally decided to take some time to study the Electron framework and the security considerations around it. After learning…

Nov 17, 2021
1
The tale of CVE-2021–34479 (VSCode XSS)
The tale of CVE-2021–34479 (VSCode XSS)
Nov 17, 2021
1
CodeX

Published in

CodeX

Hunting for XSS with CodeQL

What is CodeQL

Aug 28, 2021
1
Hunting for XSS with CodeQL
Hunting for XSS with CodeQL
Aug 28, 2021
1
Techiepedia

Published in

Techiepedia

How I found my first Chrome bug (CVE-2021–21210)

On October 31, 2020, @SamyKamkar published his research on NAT Slipstreaming. According to his own words, NAT Slipstreaming —

Jun 28, 2021
How I found my first Chrome bug (CVE-2021–21210)
How I found my first Chrome bug (CVE-2021–21210)
Jun 28, 2021

Cracking Rolling Code Locks the lazy way

I took some of my Christmas break time to solve as many challenges as I could in HackerOne’s CTF. Out of the remaining challenges I still…

Jan 1, 2021
2
Jan 1, 2021
2
Daniel Santos

Daniel Santos

125 Followers

Security researcher and penetration tester

Following
  • Nasreddine Bencherchali

    Nasreddine Bencherchali

  • Jang

    Jang

  • frycos

    frycos

  • Ricardo Iramar dos Santos

    Ricardo Iramar dos Santos

  • IFCR

    IFCR

See all (19)

Help

Status

About

Careers

Press

Blog

Privacy

Terms

Text to speech

Teams