"Won't Fix" to Full Takeover: Escalating Self-XSS Beyond Info Severity

Apr 15, 11:00 PM – Apr 16, 12:00 AM (UTC)

Brazil HackerOne Club

Hacking Meetups

About this event!

This presentation demonstrates how an isolated Self-XSS context can be escalated into a full Account Takeover on the victim's account by chaining advanced techniques involving browser mechanics, OAuth flow manipulation, and session hijacking transforming what was once considered harmless into a high-value vulnerability.

Speakers

Gustavo

Currently working as a pentester, and in his free time dedicates himself to in-depth study of offensive security and vulnerability research in web and AI applications. Has discovered vulnerabilities across different attack surfaces at various companies, including Mercado Livre, Udemy, and Roblox.

Rafael

Worked as a pentester for 5 years, with experience in mobile and web security, and has been a full-time Bug Bounty Hunter for the past 2 years. Recognized by PortSwigger with research featured in the Top 10 Web Hacking Techniques of 2023, invited to 3 Live Hacking Events, and recognized as a top platform performer on HackerOne. Has identified vulnerabilities at companies such as PayPal, Shopify, Epic Games, and Google, with over 200 bugs reported.

Speakers

  • Gustavo Ribeiro

  • Rafael Santos

Organizers

  • Arthur Aires

    Co-Ambassador of Brazil HackerOne Club

  • Joao Teles

    Co-Ambassador of Brazil HackerOne Club

  • Sandro Garcia

    sgt_

  • Felipe Caon

    caon

Contact Us