Forwarded from digMeMore (Yasho)
حاج امید و حاج امیر این مدت رنده کردن، این فقط یکی از باگاییه که اخیرا زدن، هدفشون هم یه تک وبسایت بود و کلی هم قدمت داشت، narrow recon شون واقعا قوی بود، تکنیک اکسپلویتشون هم خفن بود، کلا عشق کردم، خلاصه مبارکتون باشه ❤️
لینک توییت:
https://x.com/voorivex/status/1888283506821697614?s=46&t=t4dmnMSh7dUAGaohytE6mQ
لینک توییت:
https://x.com/voorivex/status/1888283506821697614?s=46&t=t4dmnMSh7dUAGaohytE6mQ
👍20🔥9❤3
سال نو همتون مبارک، امیدوارم سال جدیدتون پر تجربههای خوب و خوش باشه ❤️🔥
Please open Telegram to view this post
VIEW IN TELEGRAM
❤🔥55❤7🤝2👍1🔥1
👍15🤝1
Puny-code 0-Click-Account-Takeover
https://blog.voorivex.team/puny-code-0-click-account-takeover
https://blog.voorivex.team/puny-code-0-click-account-takeover
Voorivex Team
Puny-Code, 0-Click Account Takeover
A parser disagreement between SMTP servers and MySQL casts puny-coded characters back to ASCII — turning a forgot-password flow into a 0-click account takeover.
❤8
https://x.com/AmirMSafari/status/1916915937661620711
https://x.com/slonser_/status/1933563335347249343
https://blog.slonser.info/posts/make-self-xss-great-again/
https://x.com/slonser_/status/1933563335347249343
https://blog.slonser.info/posts/make-self-xss-great-again/
X (formerly Twitter)
slonser (@slonser_) on X
My new research
Escalation of Self-XSS to XSS using modern browser capabilities.
https://t.co/aYKhHAeCcq
Escalation of Self-XSS to XSS using modern browser capabilities.
https://t.co/aYKhHAeCcq
❤7
https://x.com/YShahinzadeh/status/1954258737423614164
https://blog.voorivex.team/hacking-veeam-several-cves-and-30k-bounties
https://blog.voorivex.team/hacking-veeam-several-cves-and-30k-bounties
X (formerly Twitter)
Yasho (@YShahinzadeh) on X
I’m a web guy, so I usually don’t work on non-web applications since my mind doesn’t do binary. With the help of my friend for reverse engineering, I managed to uncover some CVEs. It was very challenging for me, hope you like it:
https://t.co/xRRCoO8JFP
https://t.co/xRRCoO8JFP
❤18
❤10👎3⚡1👍1🔥1
پرایوت وردلیست:
https://x.com/ImAyrix/status/1998448300530479270
https://x.com/ImAyrix/status/1998448300530479270
X (formerly Twitter)
Amirabbas Ataei (@ImAyrix) on X
For the past year, I've been using a private wordlist generated from actual bug bounty reports.
I grabbed disclosed report texts by simply appending .json to the report URLs (as shown below) and fed them into fallparams to mine parameters from the included…
I grabbed disclosed report texts by simply appending .json to the report URLs (as shown below) and fed them into fallparams to mine parameters from the included…
❤17🔥3🤣2