You are here |
marcus-obst.de | ||
| | | |
localghost.dev
|
|
| | | | A guide to cross-site scripting (XSS) attacks and the HTTP Content-Security-Policy header, what it does, how to use it, and how it protects us. | |
| | | |
mmazzarolo.com
|
|
| | | | I recently learned that Content Security Policy (CSP) violations are reported differently depending on the browser being used. | |
| | | |
blog.freeradical.zone
|
|
| | | | I'm serving Free Radical's images etc. from S3. When I updated to Mastodon v2.1.0, I noticed that all the page's images were missing. Safari's Show JavaScript Console menu revealed a lot of errors like: [Error] Refused to load https://s3-us-west-2.amazonaws.com/freeradical-system/accounts/avatars/000/014/309/static/91f9782fad3f6284.png because it does not appear in the img-src directive of the Content Security Policy. Turns out that some time between the releases of v2.0.0 and v2.1.0, the Mastodon switch... | |
| | | |
thehackernews.com
|
|
| | Researchers Demonstrated New Way to Catch Advanced MITM Phishing Toolkits in the Wild |