Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
albertpedersen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
A revisit of remote Spectre attacks on Cloudflare Workers
(blog.cloudflare.com)
76 points
by
albertpedersen
2mo ago
|
5 comments
2.
▲
CookieStore
(developer.mozilla.org)
2 points
by
albertpedersen
1y ago
|
1 comments
3.
▲
by
albertpedersen
1y ago
Starting with Firefox 140, the Cookie Store API is a baseline feature: https://caniuse.com/cookie-store-api
4.
▲
Map of Long-Distance Train Services in Germany 2025
(larstransportmaps.com)
5 points
by
albertpedersen
1y ago
|
0 comments
5.
▲
Confused Deputy Vulnerability in Cloudflare CASB
(albertpedersen.com)
3 points
by
albertpedersen
3y ago
|
1 comments
6.
▲
by
albertpedersen
3y ago
This is the write-up of a critical vulnerability I discovered in Cloudflare CASB that enabled me to view sensitive information about other customers’ Microsoft and GitHub organizations, including employee names/emails, links to SharePo
7.
▲
Cloudflare's handling of a bug in interpreting IPv4-mapped IPv6 addresses
(blog.cloudflare.com)
8 points
by
albertpedersen
4y ago
|
2 comments
8.
▲
by
albertpedersen
4y ago
Link to the report on HackerOne: https://hackerone.com/reports/1785260
9.
▲
by
albertpedersen
4y ago
The bug was initially reported to Cloudflare's private bug bounty program since there was no public program at the time. Like it or not, the private program does not have the same disclosure policy as the public program does. In early
10.
▲
by
albertpedersen
4y ago
Yup, 'Burp' refers to the free version of 'Burp Suite'. I don't use Burp Suite anymore though. Some months ago I started using mitmproxy ( https://github.com/mitmproxy/mitmproxy ) due to it'
11.
▲
by
albertpedersen
4y ago
In this case the second $3000 bounty was due to a 2x promotion at the time. The guideline for a critical is $3000, but Cloudflare does occasionally award bonuses for severe vulnerabilities (e.g. https://hackerone.com/reports
12.
▲
by
albertpedersen
4y ago
Here's the write-up of a simple but severe exploit I found in Cloudflare's email forwarding service.
13.
▲
Hijacking Email with Cloudflare Email Routing
(albertpedersen.com)
262 points
by
albertpedersen
4y ago
|
83 comments