Konstantin 
I'm a hacker and mainly post about web security.
By profession, I am a pentester and team leader @usdAG@infosec.exchange.
I like to explain and understand things and I am convinced that the two go hand in hand.
So my posts are mostly of an educational nature.
Lately, I spend most of my free time developing CVE Crowd.
⎯⎯⎯⎯⎯⎯
Recent topics:
#CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP
Apparently #Safari on #iOS applies img-src directives of the content security policy to *object tags* that load images like so: https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/551/708/143/302/638/original/8f107909c923fd55.png">
This was the reason, why https://cvecrowd.com did not display avatars on iOS devices: I was using object tags and the object-src directive.
Fixed it by adding an img-src directive as well.
Damn! Close enough.
I solved the daily #CluesBySam, May 31st 2026 (Hard), in less than 13 minutes
🟨🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
Finally a perfect solve again
I solved the daily #CluesBySam, May 27th 2026 (Medium), in less than 9 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
Anyone else having the issue that avatars on https://cvecrowd.com are not loading on a mobile device?
Perfect streak: 2 😊
I solved the daily #CluesBySam, Jun 2nd 2026 (Medium), in 04:42
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
One reason to look forward to mondays. Easy Clues by Sam puzzles.
I solved the daily #CluesBySam, Jun 1st 2026 (Easy), in 05:23
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
This one was cumbersome. Had an early error… This always tempts me to use hints because a perfect solve isn‘t possible anymore.
I solved the daily #CluesBySam, May 30th 2026 (Hard), in less than 14 minutes
🟩🟩🟩🟩
🟩🟨🟩🟩
🟠🟩🟩🟡
🟩🟨🟩🟩
🟩🟠🟩🟩
https://cluesbysam.com
Perfect streak gone. But I'm still happy with today’s result, given the advanced difficulty 😊
I solved the daily #CluesBySam, May 29th 2026 (Tricky), in less than 8 minutes
🟩🟩🟩🟨
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
Perfect solve streak: 2 🎉
I solved the daily #CluesBySam, May 28th 2026 (Tricky), in less than 13 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com
@me@infosec.exchange Who are "some people"? :)
Attack Complexity (AC) measures actions taken by the attacker to actively circumvent existing built-in security-enhancing conditions.
What kind of circumvention and evasion must be fulfilled? As far as I see there aren't any.
Attack Requirements (AT) emerge naturally as a consequence of the deployment, not explicitly as an attack mitigation.
According to your argument, it's always AT: Present because every attack requires the attacker to use and setup a computer.
For the scoring to work, you have to assume the most powerful attacker possible, who of course has already set up a rouge password reset URL.
As I said, the only real requirement is the knowledge of an existing email address. With billions of leaked email addresses on the Internet, I am not sure this is a hard requirement to overcome.
