■■■□□ #GoodRead
https://medium.com/@linasvaliukas/by-the-way-the-list-of-ssl-tls-certificates-issued-to-you-including-subdomains-is-public-5537ef1f11f5
https://medium.com/@linasvaliukas/by-the-way-the-list-of-ssl-tls-certificates-issued-to-you-including-subdomains-is-public-5537ef1f11f5
Medium
By the way, the list of SSL/TLS certificates issued to you (including subdomains) is public!
Are you comfortable with the fact that others can find out about your production environment simply by querying a public database?
■■■■■ #BreakDown of #iPhone #hack
#GoodRead #Muslim #Uighur #CyberWar #opression #China #Google #P0
https://www.wired.com/story/ios-hacks-apple-response/amp
#GoodRead #Muslim #Uighur #CyberWar #opression #China #Google #P0
https://www.wired.com/story/ios-hacks-apple-response/amp
WIRED
Apple Defends iOS Security a Week After Hacking Campaign
In its first public statement since Google revealed a sophisticated attack against iOS devices, Apple defended its security measures.
■■■■□ #PDF #HTTP Request Smuggling #HRS Document Dated: 2005
https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf
https://www.cgisecurity.com/lib/HTTP-Request-Smuggling.pdf
■■■□□ #GoodReport
#xh3n1
https://hackerone.com/reports/638635
Disclosed at: 2019-09-08 09:55:04 UTC+0
Created at: 2019-07-09 23:30:54 UTC+0
#xh3n1
Insecure Zendesk SSO implementation by generating JWT client-side https://hackerone.com/reports/638635
Disclosed at: 2019-09-08 09:55:04 UTC+0
Created at: 2019-07-09 23:30:54 UTC+0
HackerOne
Trint Ltd disclosed on HackerOne: Insecure Zendesk SSO...
## Summary:
app.trint.com implements SSO to Zendesk, it does this by using JWT as described at...
app.trint.com implements SSO to Zendesk, it does this by using JWT as described at...
■■■□□ #WordPress fixes severe #XSS for in update
https://securityaffairs.co/wordpress/90967/security/wordpress-5-2-3.html
https://securityaffairs.co/wordpress/90967/security/wordpress-5-2-3.html
Security Affairs
WordPress 5.2.3 fixes multiple issues, including some severe XSS flaws
The WordPress development team released version 5.2.3 that includes 29 fixes and enhancements and several security patches.
■■■□□ #interesting piece of #information
#Apple opened a dedicated #datacenter in mainland #China and handed control to a state backed company.
Source: MawareTech
#Apple opened a dedicated #datacenter in mainland #China and handed control to a state backed company.
Source: MawareTech
■■■■□ #funny #DayTripper: A utility that closes ask your Windows on a physical event like a for open; uses physical laser sensors.
https://blog.hackster.io/daytripper-laser-tripwire-hides-all-of-your-windows-1927d649893a
https://blog.hackster.io/daytripper-laser-tripwire-hides-all-of-your-windows-1927d649893a
Hackster.io
Daytripper Laser Tripwire Hides All of Your Windows
As described on it’s Tindie product listing, “Do you always slack off on your computer and worry about getting busted? Not anymore because…
Forwarded from 🔥 Red Team Zone | Wiki🔥
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from 🔥 Red Team Zone | Wiki🔥
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from 🔥 Red Team Zone | Wiki🔥
Please open Telegram to view this post
VIEW IN TELEGRAM
Forwarded from 🔥 Red Team Zone | Wiki🔥
Please open Telegram to view this post
VIEW IN TELEGRAM
■■■■□ #BugBounty #GoodReport #LPE
From real
https://hackerone.com/reports/520903
Disclosed at: 2019-09-11 09:46:31 UTC+0
Created at: 2019-04-02 15:17:43 UTC+0
From real
Apache HTTP [2.4.17-2.4.38] Local Root Privilege Escalation https://hackerone.com/reports/520903
Disclosed at: 2019-09-11 09:46:31 UTC+0
Created at: 2019-04-02 15:17:43 UTC+0
HackerOne
Internet Bug Bounty disclosed on HackerOne: Apache HTTP...
Hello,
I reported a Local Root privilege escalation vulnerability on Apache HTTPd at the beginning of the year. Apache has now patched it, [as you can see...
I reported a Local Root privilege escalation vulnerability on Apache HTTPd at the beginning of the year. Apache has now patched it, [as you can see...