Ayrix Bytes
947 subscribers
8.82K photos
209 links
Download Telegram
🔹 NahamCon – Trash the Cache Write-up (Web 1000)

📆 Sun, 14 Jun 2020 21:09:18 +0000

#️⃣ #Uncategorized #CTF #nahamcon
🔹 JosieBellini’s Yours Truly Puzzle Walkthrough

📆 Tue, 03 Mar 2020 15:16:32 +0000

#️⃣ #Uncategorized #age_of_rust #axies_infinity #crypto #cryptokittens #neon_district #puzzle
🔹 A Tale of Exploitation in Spreadsheet File Conversions

📆 Fri, 18 Oct 2019 21:03:37 +0000

#️⃣ #Uncategorized
🔹 H1-5411 CTF Write-up by erbbysam and ziot

📆 Mon, 08 Oct 2018 16:58:55 +0000

#️⃣ #Uncategorized
🔹 Authentication bypass on Uber’s Single Sign-On via subdomain takeover

📆 Sun, 25 Jun 2017 01:26:38 +0000

#️⃣ #Web_Security
🔹 Authentication bypass on Airbnb via OAuth tokens theft

📆 Thu, 22 Jun 2017 01:18:21 +0000

#️⃣ #Web_Security
🔹 Authentication bypass on Ubiquity’s Single Sign-On via subdomain takeover

📆 Tue, 29 Nov 2016 08:42:14 +0000

#️⃣ #Web_Security
🔹 Hack.LU 2016 CTF DataOnly Writeup

📆 Fri, 21 Oct 2016 00:02:52 +0000

#️⃣ #Exploit_Development #Research #hacklu16 #writeup
🔹 Hack.LU 2016 CTF CthCoin Writeup

📆 Thu, 20 Oct 2016 14:26:08 +0000

#️⃣ #Web_Security #hacklu16 #writeup
🔹 How My Rogue Android App Could Monitor & Brute-force Your App’s Sensitive Metadata

📆 Thu, 08 Sep 2016 18:07:08 +0000

#️⃣ #Mobile_Security
🔹 How I Could Steal Money from Instagram, Google and Microsoft

📆 Fri, 15 Jul 2016 00:54:20 +0000

#️⃣ #Web_Security
🔹 HackerOne Web Authentication Endpoint Credentials Brute-Force Vulnerability

📆 Mon, 27 Jun 2016 10:48:23 +0000

#️⃣ #Web_Security
🔹 InstaBrute: Two Ways to Brute-force Instagram Account Credentials

📆 Thu, 19 May 2016 21:22:45 +0000

#️⃣ #Mobile_Security #Web_Security
🔹 How I Could Compromise 4% (Locked) Instagram Accounts

📆 Sun, 27 Mar 2016 22:27:59 +0000

#️⃣ #Web_Security
🔹 My Exciting Two Month Journey as a Security Analyst at Appsecco

📆 Wed, 09 Aug 2023 12:35:22 GMT

#️⃣ #careers #hacking #cybersecurity #working_with_appsecco #culture
🔹 Exploiting IAM security Misconfigurations — Part 2

📆 Tue, 18 Jul 2023 05:24:01 GMT

#️⃣ #exploitation #aws #aws_security #cloud_security #hacking
🔹 Getting shell and data access in AWS App Runner

📆 Mon, 29 May 2023 16:08:31 GMT

#️⃣ #privilege_escalation #hacking #aws #apprunner #cloud_security
🔹 Exploiting IAM security Misconfigurations — Part 1

📆 Thu, 18 May 2023 06:18:42 GMT

#️⃣ #aws_security #exploitation #cloud_security #hacking #aws_policies
1
چند روز پیش یه چلنج XSS توییت کردم که راه حلش میشد این پیلود:
https://ayrix.info/xss.php?l01=javascript://\x250aalert`XSS`

اما حالا توی پارامتر l02 دیگه از x\ نمیتونید استفاده کنید :)
دوست داشتید روش وقت بزارید و بزنیدش باحاله❤️
13👍3👌1🍾1
این پیلود رو امروز شانسی دیدم:
[2023].find(alert)
کاربردی که خیلی نیست ولی خب جالبه :)
👍172😁1🆒1