<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web-Security on Nikita Sveshnikov</title>
    <link>https://nicksv.com/tags/web-security/</link>
    <description>Recent content in Web-Security on Nikita Sveshnikov</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 29 Dec 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nicksv.com/tags/web-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Our PDF Generator Security Research Is Out</title>
      <link>https://nicksv.com/posts/pdf-generator-research/</link>
      <pubDate>Mon, 29 Dec 2025 00:00:00 +0000</pubDate>
      <guid>https://nicksv.com/posts/pdf-generator-research/</guid>
      <description>&lt;p&gt;The article on our research from the first half of this year is finally published: &lt;a href=&#34;https://swarm.ptsecurity.com/blind-trust-what-is-hidden-behind-the-process-of-creating-your-pdf-file/&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Blind trust: what is hidden behind the process of creating your PDF file?&lt;/a&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>java.net.URL.equals() — A Hidden Vulnerability in Whitelist Checks</title>
      <link>https://nicksv.com/posts/java-url-equals-vulnerability/</link>
      <pubDate>Sun, 06 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://nicksv.com/posts/java-url-equals-vulnerability/</guid>
      <description>&lt;h2 id=&#34;tldr&#34;&gt;TL;DR&lt;/h2&gt; &lt;p&gt;&lt;code&gt;java.net.URL.equals()&lt;/code&gt; performs a DNS lookup and considers two URLs equal if their IP addresses match — even when the domains are completely different. This can bypass whitelist checks and lead to SSRF or DNS rebinding attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub Security Lab References My CORS Research</title>
      <link>https://nicksv.com/posts/github-security-lab-cors/</link>
      <pubDate>Sat, 05 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://nicksv.com/posts/github-security-lab-cors/</guid>
      <description>&lt;p&gt;GitHub Security Lab published an article on localhost dangers, CORS and DNS rebinding — and they directly reference and recommend my research on CORS misconfiguration attacks.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
