Ayrix Bytes
947 subscribers
8.82K photos
209 links
Download Telegram
πŸ”Ή Dependabot Confusion: Gaining Access to Private GitHub Repositories using Dependabot

πŸ“† 2023-05-06

#️⃣ #Dependency_confusion
πŸ”Ή CSS Injection via PostMessages to stealing Credit Card Info

πŸ“† 2023-05-05

#️⃣ #postMessage
πŸ”Ή Bullied by Bugcrowd over Kape CyberGhost disclosure

πŸ“† 2023-05-05

#️⃣ #Local_Privilege_Escalation
πŸ”Ή Cookie Bugs - Smuggling & Injection

πŸ“† 2023-05-05

#️⃣ #Cookie_smuggling
πŸ”Ή Privilege Escalations through Integrations

πŸ“† 2023-05-05

#️⃣ #postMessage
πŸ”Ή When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities

πŸ“† 2023-05-04

#️⃣ #SSRF
πŸ”Ή The Art of Information Disclosure: A Deep Dive into CVE-2022-37985, a Unique Information Disclosure Vulnerability in Windows Graphics Component

πŸ“† 2023-05-03

#️⃣ #Out_of_bounds_Read
πŸ”Ή AWS Identity Center (formerly known as AWS SSO): A Guide to Privilege Escalation and Identity and Access Management

πŸ“† 2023-05-01

#️⃣ #Privilege_escalation
πŸ”Ή TENDA–N301-v6–(CVE-2023–29680,CVE-2023–29681)

πŸ“† 2023-04-30

#️⃣ #Sensitive_Information_Sent_Over_an_Unencrypted_Channel
πŸ”Ή New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP)

πŸ“† 2023-04-25

#️⃣ #DoS
πŸ”Ή How Material Security Uncovered a Vulnerability in the Gmail API

πŸ“† 2023-04-18

#️⃣ #Broken_Access_Control
πŸ”Ή From Django Debug Mode to PII Data Leak of more than 500+ Employees due Broken Access Control and IDOR

πŸ“† 2023-04-14

#️⃣ #Debug_mode_enabled
πŸ”Ή Bypassing OGNL sandboxes for fun and charities

πŸ“† 2023-01-27

#️⃣ #OGNL_injection
πŸ”Ή Azure Active Directory Flaw Allowed SAML Persistence

πŸ“† 2023-01-18

#️⃣ #Azure_AD
πŸ”Ή APT HackTheBox | Detailed Writeup (Foothold)

πŸ“† Mon, 08 May 2023 19:46:31 GMT

#️⃣ #cybersecurity #hackthebox #ctf #active_directory #writeup
πŸ”Ή Bypassing Protocol Concatenation in SSRF: Strategies for Testing Vulnerable Applications

πŸ“† Mon, 08 May 2023 19:29:41 GMT

#️⃣ #bug_bounty_tips #bug_bounty
πŸ”Ή ОновлСння DeGate Π·Π° ΠΊΠ²Ρ–Ρ‚Π΅Π½ΡŒ 2023 Ρ€.

πŸ“† Mon, 08 May 2023 19:09:26 GMT

#️⃣ #dex #ethereum #mainnet #degate #bug_bounty
πŸ”Ή Sorting Your Way to Stolen Passwords

πŸ“† Mon, 08 May 2023 19:03:30 GMT

#️⃣ #bug_bounty #software_development #hacking #penetration_testing #cybersecurity
πŸ”Ή Account Takeover via Signup Feature

πŸ“† Mon, 08 May 2023 20:14:19 GMT

#️⃣ #bug_bounty_writeup #bugs #bug_bounty #bug_bounty_tips #bug_fixes
πŸ”Ή Full Account takeover (even for admins)

πŸ“† Mon, 08 May 2023 20:09:48 GMT

#️⃣ #bug_fixes #bugs #bug_bounty_writeup #bug_bounty_tips #bug_bounty
πŸ”Ή Admin Account Takeover worth $5,657

πŸ“† Mon, 08 May 2023 20:03:38 GMT

#️⃣ #bugs #bug_bounty_tips #bug_fixes #bug_bounty_writeup #bug_bounty