<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Web on Investigations by 0xFantasy</title>
		<link>http://blog.fa.nta.sy/tags/web/</link>
		<description>Recent content in Web on Investigations by 0xFantasy</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Thu, 28 May 2026 19:34:33 -0400</lastBuildDate>
		
			<atom:link href="http://blog.fa.nta.sy/tags/web/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Google: You Get an Open Redirect! You Get an Open Redirect!</title>
				<link>http://blog.fa.nta.sy/posts/2026-05-28-google-redirects/</link>
				<pubDate>Thu, 28 May 2026 19:34:33 -0400</pubDate>
				<guid>http://blog.fa.nta.sy/posts/2026-05-28-google-redirects/</guid>
				<description>Google has a multitude of open redirects that are frequently abused by threat actors. They are used to both deter initial URL scanning and obfuscate the final phishing URL. A recent example of this in the wild found by KnowBe4 showcased combining multiple redirects in a row. Google seemingly has no interest in fixing these issues according to their VRP. These redirects span different Google domains and products including Search, Meet and Ads (formerly DoubleClick).</description>
			</item>
			<item>
				<title>Trump Mobile: God Mode API Endpoint, Plaintext Passwords, and Mobile Device Identifiers</title>
				<link>http://blog.fa.nta.sy/posts/2026-05-20-trump-mobile-god-mode/</link>
				<pubDate>Wed, 20 May 2026 11:16:29 -0400</pubDate>
				<guid>http://blog.fa.nta.sy/posts/2026-05-20-trump-mobile-god-mode/</guid>
				<description>For an indeterminate amount of time, the Trump Mobile API had at least two unprotected endpoints that could be exploited for either a) mass general info disclosure or b) targeted and enumerable info disclosure including plain text passwords; full PII including name, address, and email; and unique mobile device identifiers inlcuding IMEI and ICCID.</description>
			</item>
			<item>
				<title>No, your phishing kit does not have a Cloudflare bypass</title>
				<link>http://blog.fa.nta.sy/posts/2026-04-13-not-a-cloudflare-bypass/</link>
				<pubDate>Mon, 13 Apr 2026 16:05:35 -0400</pubDate>
				<guid>http://blog.fa.nta.sy/posts/2026-04-13-not-a-cloudflare-bypass/</guid>
				<description>Through my daily work and from reading quite a few blog posts, researchers consistently mistake that a phishing kit is leveraging /cdn-cgi/phish-bypass to hinder web and security scanners. This stems from a misunderstanding of what the Cloudflare /cdn-cgi/ endpoint is and how it operates.</description>
			</item>
	</channel>
</rss>
