Copy
Hey, it's EdOverflow!

I often find myself checking Content Security Policies for new hosts that could potentially be in scope. In order to facilitate this process and make it scale, I have written a small utility here: https://github.com/EdOverflow/csp. Simply create a text file with all the URLs you want to fetch whitelisted hosts from and run the following:
$ cat hosts.txt
http://example.com/
$ cat hosts.txt | csp
example.com
subdomain.example.com

Hope this helps! Have fun. :)
Support my work

If you enjoy reading my write-ups and would like to support my work, please check out my "Buy me a coffee" page. By supporting me, you allow me to continue sharing research and keep my blog ad-free. You can get more bug bounty tips and tricks at buymeacoffee.com/edoverflow. Thank you for your support. :)
 
Buy Me A Coffee ☕
To make sure you get future emails add contact@edoverflow.com to your contact list. Even if this email isn't in spam now it could easily end up there in the future. If you’re using Gmail drag this email from your “Promotions” folder to your “Primary” folder.

Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list.






This email was sent to <<Email Address>>
why did I get this?    unsubscribe from this list    update subscription preferences
EdOverflow · Zürich · Zürich 8092 · Switzerland

Email Marketing Powered by Mailchimp