/rest/settings?blah.settings.db.passwd
/rest/settings?blah.settings.ssh.passwd
add to your wordlist
اگه فقط یک روز به عمرم مونده باشه کل ابزارایی که نوشتم رو از Python به C پورت میکنم
IDORacle.pdf
657.9 KB
#AppSec
#Research
#WebApp_Security
"IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026.
]-> https://github.com/GuanhangShiFDU/IDOR-GUARD
// Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow
#Research
#WebApp_Security
"IDORacle: Template-Guided SQL-Sink Mediation for Object-Level Authorization in Java Applications", Sep 2026.
]-> https://github.com/GuanhangShiFDU/IDOR-GUARD
// Cross-language IDOR reproduction and defense demo for Java, Python, Go, and PHP applications. Evaluated applications include XXL-Job, RuoYi, BootDo, wger, Gitea, Krayin, and Langflow
اقا درود
بعد از ساخت open-redirect-lab به ذهنم زد شروع کنم به نوبت تمام lab های owasp رو بسازم.
چون هر آسیب پذیری که می رفتم روش دیپ بشم یا lab نبود اگرم بود تمام مباحث رو کاور نمی کرد.
و زمان گیر بود که هی بخوای برای هر آسیب پذیری کلی بگردی که یه lab خوب پیدا کنی.
به همین دلیل شروع کردم به استارت زدن این lab ها که هم خودم هم بچه های این فیلد بتونن استفاده ببرن.
الانم امدم CSRF رو کاور دادم با 10 لول طبقه بندی شده.
که به شما یاد می ده چجوری می تونید به CSRF برسید و حتا دسترسی خودتونو بالا ببرید و به باگ های دیگه برسید.
🟢 LEVEL 1: GET Method State Change
🟢 LEVEL 2: POST Method State Change
🟡 LEVEL 3: Weak Referer Validation
🟡 LEVEL 4: Token Omission Logic Flaw
🔴 LEVEL 5: Detached Session Token
🔴 LEVEL 6: Double Submit Cookie Flaw
🔴 LEVEL 7: JSON Payload CSRF
🔴 LEVEL 8: SameSite Lax loose-method Bypass
🔴 LEVEL 9: SameSite Bypass via Open Redirect
🟣 LEVEL 10: CSRF to Full Account Takeover (Final Boss)
اگر دوست داشتید خودتونو به چالش بکشید😉
https://github.com/zoly-zoly/CSRF-Lab
بعد از ساخت open-redirect-lab به ذهنم زد شروع کنم به نوبت تمام lab های owasp رو بسازم.
چون هر آسیب پذیری که می رفتم روش دیپ بشم یا lab نبود اگرم بود تمام مباحث رو کاور نمی کرد.
و زمان گیر بود که هی بخوای برای هر آسیب پذیری کلی بگردی که یه lab خوب پیدا کنی.
به همین دلیل شروع کردم به استارت زدن این lab ها که هم خودم هم بچه های این فیلد بتونن استفاده ببرن.
الانم امدم CSRF رو کاور دادم با 10 لول طبقه بندی شده.
که به شما یاد می ده چجوری می تونید به CSRF برسید و حتا دسترسی خودتونو بالا ببرید و به باگ های دیگه برسید.
🟢 LEVEL 1: GET Method State Change
🟢 LEVEL 2: POST Method State Change
🟡 LEVEL 3: Weak Referer Validation
🟡 LEVEL 4: Token Omission Logic Flaw
🔴 LEVEL 5: Detached Session Token
🔴 LEVEL 6: Double Submit Cookie Flaw
🔴 LEVEL 7: JSON Payload CSRF
🔴 LEVEL 8: SameSite Lax loose-method Bypass
🔴 LEVEL 9: SameSite Bypass via Open Redirect
🟣 LEVEL 10: CSRF to Full Account Takeover (Final Boss)
اگر دوست داشتید خودتونو به چالش بکشید😉
https://github.com/zoly-zoly/CSRF-Lab
🔴 1.4Billion Credential Records Exposed Online
A misconfigured Elasticsearch instance exposed 360+GB of data, including ~1.4Billion credential records and 1.3M+ US consumer PII records containing names, emails, phone numbers and addresses.
The infrastructure appears to aggregate and categorize data from multiple sources, including Telegram channels, potentially making credentials searchable by targets such as banking and crypto services.
Its operator and intended purpose remain unknown - it could potentially support anything from data/intelligence services to malicious operations.
#ThreatIntel #CyberSecurity #DataBreach
A misconfigured Elasticsearch instance exposed 360+GB of data, including ~1.4Billion credential records and 1.3M+ US consumer PII records containing names, emails, phone numbers and addresses.
The infrastructure appears to aggregate and categorize data from multiple sources, including Telegram channels, potentially making credentials searchable by targets such as banking and crypto services.
Its operator and intended purpose remain unknown - it could potentially support anything from data/intelligence services to malicious operations.
#ThreatIntel #CyberSecurity #DataBreach
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
https://pwn.ai/blog/click2shell
https://pwn.ai/blog/click2shell
PWN.AI
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain
A pre-authentication Theme Injection to RCE chain in WordPress Core that allows unauthenticated attackers to achieve remote code execution on any default WordPress installation through a single click.
https://medium.com/@edemzayaniyt/how-a-sort-parmeter-became-blind-sql-injection-6c2ffe0ec457
https://medium.com/@h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8
https://medium.com/@h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8
Medium
How a Sort Parameter Became Blind SQL Injection
How a Sort Parameter Became Blind SQL Injection Hello everyone 👋 While testing a web application in scope for a private program, I came across a REST API endpoint used to return a list of records …
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
https://gbhackers.com/new-cache-key-injection-attack/
https://gbhackers.com/new-cache-key-injection-attack/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages.
Forwarded from 🕸 Articles
zseano-methodology.pdf
8.9 MB