28 May 2019

/ 1-click RCE with Skype Web Plugin and Qt apps

Earlier this year, I’ve heard that you could send links with custom URI schemes through Discord, that can trigger without the user’s confirmation when using desktop clients. I’ve been experimenting with URI schemes ever since, I wanted to see how far I can push it in terms of exploitability, a... [ Read more ]