ZipJar, a little bit unexpected attack chain
The upcoming .zip TLDs from Google brought some discussion about attack vectors. Most of those attack vectors are not completely new, like using an "@" to split between username and host. While playing a little bit around, an unexpected attack chain ...
cyvisory.hashnode.dev7 min read