<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on EthanH</title><link>https://ethanh.co.za/posts/</link><description>Recent content in Posts on EthanH</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>EthanH</copyright><lastBuildDate>Sat, 10 Jan 2026 15:10:34 +0000</lastBuildDate><atom:link href="https://ethanh.co.za/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Persistence or Snake-oil: Re-achieving Persistent XSS</title><link>https://ethanh.co.za/posts/persistence-or-snakeoil/</link><pubDate>Sat, 10 Jan 2026 15:10:34 +0000</pubDate><guid>https://ethanh.co.za/posts/persistence-or-snakeoil/</guid><description>Boring old XSS During 2025 I was determined to understand what it meant to have persistence within a web environment. This led me down a massive rabbit hole&amp;hellip; from navigation hooking to service worker attacks, I ventured forth. In the end, we managed not only to persist past navigation, but managed to persist our control over a victims browsing session even after browser close.
I had the opportunity to present the research output at the following conferences:</description></item><item><title>TryHackMe NoScope Early Access Partner</title><link>https://ethanh.co.za/posts/thm-noscope/</link><pubDate>Sat, 10 Jan 2026 15:10:34 +0000</pubDate><guid>https://ethanh.co.za/posts/thm-noscope/</guid><description>Rise of the Pentest Agents I was fortunate enough to be apart of the NoScope pentesting agent early access development program backed by TryHackMe. Regardless of the potential controversy that was stirred up with the release of this solution, I hold firm that pentesting agents can improve the workflow of human pentesters if given direction, and can be used as a force for good to secure the world!
I strongly believe in the potential NoScope has, having witnessed it first hand.</description></item><item><title>Breaking the Barrier Part 2</title><link>https://ethanh.co.za/posts/breaking-the-barrier-p2/</link><pubDate>Tue, 10 Dec 2024 15:10:34 +0000</pubDate><guid>https://ethanh.co.za/posts/breaking-the-barrier-p2/</guid><description>The Star Wars Sequel During Bsides Cape Town this year, I was fortunate enough to be a speaker there and had the opportunity to present the outcomes of my initial research that focused on web application firewalls and the modern state of WAFs.
In the talk we took a look at a high level history of the evolution of WAFs as well as the growth of the techniques they use to detect and repel malicious behavior.</description></item><item><title>Breaking the Barrier: Exploring WAF Bypass Vulnerabilities</title><link>https://ethanh.co.za/posts/breaking-the-barrier/</link><pubDate>Tue, 23 Jul 2024 23:30:00 +0600</pubDate><guid>https://ethanh.co.za/posts/breaking-the-barrier/</guid><description>Cracking the Shield: WAF Bypass Techniques Unveiled Introduction Web Application Firewalls (WAFs) play a crucial role in safeguarding web applications by filtering and monitoring HTTP traffic between a web application and the internet. They are designed to protect against various web-based attacks, such as SQL injection, cross-site scripting (XSS), and other attacks.
However, as with any security measure, WAFs are not infallible. The constant evolution of attack techniques means that even the most robust WAFs can be bypassed under certain conditions.</description></item><item><title>Exploiting the Complex: The WikiJs CSTI Vulnerability</title><link>https://ethanh.co.za/posts/exploiting-the-context/</link><pubDate>Tue, 23 Jul 2024 23:30:00 +0600</pubDate><guid>https://ethanh.co.za/posts/exploiting-the-context/</guid><description>Exploiting the Complex: The WikiJs CSTI Vulnerability Preface In today&amp;rsquo;s tech landscape, integrating front-end and back-end technologies often necessitates complex systems. However, these intricate systems can also introduce new and exotic vulnerabilities. In this post, we&amp;rsquo;ll explore a case where a sophisticated yet complex system in the widely-used Wiki.js framework led to a critical 0-day vulnerability—CVE-2024-34710.
Background Wiki.js is a powerful wiki framework built with Vue.js for the front end and Node.</description></item></channel></rss>