Disabling js for the win

,or how reading the html code w/ care lead to rce through file upload

Vuk Ivanovic
InfoSec Write-ups
Published in
3 min readFeb 10, 2023

--

Javascript. Used practically everywhere, even in your washing machine (this is a joke, I think (: ) And if you really want to know how unavoidable it is just turn off js globally using either extension or manually, and try using any of the popular websites — good luck with that :) I mean, I had js disabled globally some time ago, and I have obvious websites whitelisted for js, which means that every now and again I find myself visiting some website that heavily relies on…

--

--

IT Security and bug bounty hunting, knowledge collector especially anything with word quantum, and sometimes writer of fiction.