56,966 blogs ยท [ { "id": "01a08c61-6028-7388-9156-d569cb923876", "title": "The Rest of the Iceberg - Everything We've Missed About the Browser Extensions Attack Surface", "url": "https://weizman.github.io//2026/05/07/the-rest-of-the-iceberg/", "published_at": "2026-05-07T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569cc54b51b", "title": "What same origin iframes are used for?", "url": "https://weizman.github.io//2024/12/04/same-origin-realms-practical-usage/", "published_at": "2024-12-04T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569ccaa26ae", "title": "Is client side security dead - or a crucial part of the future?", "url": "https://weizman.github.io//2024/02/10/client-side-future/", "published_at": "2024-02-10T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569cd7dcd42", "title": "MetaMask Wallet Security Threat Model - The Browser's Prespective [๐•]", "url": "https://weizman.github.io//2024/01/21/browsers-wallet-security-debunk/", "published_at": "2024-01-21T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569ce618837", "title": "Javascript Anti Debugging - Crashing the Devtools [๐•]", "url": "https://weizman.github.io//2023/11/14/anti-debug-3/", "published_at": "2023-11-14T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569ce884606", "title": "The Same Origin Concern - presenting to W3C [๐•]", "url": "https://weizman.github.io//2023/10/03/w3c-realms/", "published_at": "2023-10-03T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569cea217b0", "title": "The Same Origin Concern", "url": "https://weizman.github.io//2023/09/28/the-same-origin-concern/", "published_at": "2023-09-28T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569cf5b4d57", "title": "Snow stops playing nice - security first at the cost of everything else", "url": "https://weizman.github.io//2023/08/03/snow-stops-playing-nice/", "published_at": "2023-08-03T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569cff3c06a", "title": "Proto Tree ๐ŸŒณ - A Way to Observe the JS Prototype Chain [๐•]", "url": "https://weizman.github.io//2023/07/27/proto-tree/", "published_at": "2023-07-27T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d044ea01", "title": "MetaMask JavaScript Security Stack (Part 3 - Snow) [๐•]", "url": "https://weizman.github.io//2023/07/14/snow/", "published_at": "2023-07-14T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d05fe91e", "title": "MetaMask JavaScript Security Stack (Part 2 - Snow) [๐•]", "url": "https://weizman.github.io//2023/07/07/snow/", "published_at": "2023-07-07T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d0fe8ac3", "title": "MetaMask JavaScript Security Stack (Part 1 - scuttling) [๐•]", "url": "https://weizman.github.io//2023/06/30/scuttling/", "published_at": "2023-06-30T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d182a539", "title": "DOM Clobbering - but with numbers?! [๐•]", "url": "https://weizman.github.io//2023/06/23/n-clob/", "published_at": "2023-06-23T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d1871d98", "title": "LavaTube - Expermintal JS tool for recursively walk through ???", "url": "https://weizman.github.io//2023/05/14/lavatube-intro/", "published_at": "2023-05-14T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d18c1a1f", "title": "CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score", "url": "https://weizman.github.io//2023/04/10/snyk-xss/", "published_at": "2023-04-10T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d19ad405", "title": "CVE-2023-1767 - Stored XSS on Snyk Advisor service can allow full fabrication of npm packages health score [๐•]", "url": "https://weizman.github.io//2023/04/09/snyk-xss/", "published_at": "2023-04-09T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d22bdc90", "title": "Introducing Snow โ„๏ธ [๐•]", "url": "https://weizman.github.io//2023/01/04/intro-snow/", "published_at": "2023-01-04T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d2e3b4a4", "title": "Realms Security [๐•]", "url": "https://weizman.github.io//2022/11/19/realms-sec/", "published_at": "2022-11-19T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d3606e6e", "title": "Integrating Snow โ„๏ธ into MetaMask ๐ŸฆŠ", "url": "https://weizman.github.io//2022/11/18/snow-into-metamask/", "published_at": "2022-11-18T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d3b0351d", "title": "What is a realm in JavaScript?", "url": "https://weizman.github.io//2022/10/28/what-is-a-realm-in-js/", "published_at": "2022-10-28T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d47d66fc", "title": "Javascript Anti Debugging - Abusing Chromium Devtools Scope Pane", "url": "https://weizman.github.io//2021/09/01/js-anti-debug-2/", "published_at": "2021-09-01T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d4a946c6", "title": "My contribution attempt to the browser javascript supply chain attack problem", "url": "https://weizman.github.io//2021/07/18/securely-snow-across/", "published_at": "2021-07-18T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d4ed9dd8", "title": "CVE-2020-6519 - Chromium 83 Zero Day Full CSP Bypass Cross Platforms", "url": "https://weizman.github.io//2020/09/02/csp-vuln/", "published_at": "2020-09-02T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d52fb210", "title": "CVE-2019-18426 - WhatsApp Vulnerabilities Disclosure - Open Redirect + CSP Bypass + Persistent XSS + FS read permissions + potential for RCE", "url": "https://weizman.github.io//2020/02/14/whatsapp-vuln/", "published_at": "2020-02-14T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d5aa86de", "title": "List EVERY event that exists in the browser", "url": "https://weizman.github.io//2020/02/02/list-events/", "published_at": "2020-02-02T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d62b38fa", "title": "unload And beforeunload Events And How To Easily Debug Them Both!", "url": "https://weizman.github.io//2020/02/02/events/", "published_at": "2020-02-02T00:00:00+00:00" }, { "id": "01a08c61-6028-7388-9156-d569d63c7ef7", "title": "Javascript Anti Debugging - Abusing SourceMappingURL", "url": "https://weizman.github.io//2019/12/18/js-anti-debug-1/", "published_at": "2019-12-18T00:00:00+00:00" } ] posts Claim your blog
Back to weizman.github.io
Blog ยท corpus.blog/blogs/weizman.github.io/posts

weizman.github.io

weizman.github.io

2026

2024

2023

2022

2021

2020

2019