hack and bug bounty
@hack_com
22
subscribers
20.9K
links
Download Telegram
Join
hack and bug bounty
22 subscribers
hack and bug bounty
ChatGPT a aidé des hackers éthiques à dénicher une faille et gagner 20’000 dollars
www.ictjournal.ch
ChatGPT a aidé des hackers éthiques à dénicher une faille et gagner 20’000 dollars
Des participants à une campagne de Bug Bounty ont remporté une prime avec le soutien de ChatGPT. Ils ont ainsi montré que l’IA générative peut être utile aux hackers éthiques.
hack and bug bounty
Practical Security Recommendations for Start-ups with Limited Budgets
Alex Chapman’s Blog
Practical Security Recommendations for Start-ups with Limited Budgets
Hi, my name is Alex, I’ve been an IT security professional since 2007 and I’ve recently entered the start-up world with my project bughuntr.io. In putting together this project, security has been a primary concern for me. This is both due to my background…
hack and bug bounty
GitLab AMA - Bug Bounty with Alex Chapman
hack and bug bounty
Bugcrowd Big Bugs: BitBucket Pipelines Kata Containers Build Container Escape
Alex Chapman’s Blog
BitBucket Pipelines Kata Containers Virtual Machine Escape
Atlassian ran a project on Bugcrowd looking for bugs in their proposed implementation of Kata Containers within the BitBucket Pipelines CI/CD environment. Whilst participating in this project, I identified a vulnerability in Kata Containers which could allow…
hack and bug bounty
Daily Swig - Container security: Privilege escalation bug patched in Docker Engine
hack and bug bounty
Moby - Access to remapped root allows privilege escalation to real root
hack and bug bounty
Kata Containers `hostPath` file write
hack and bug bounty
Privileged Container Escape - Control Groups release_agent
hack and bug bounty
Kata Containers - Improper file permissions for read-only volumes
hack and bug bounty
GitLab - GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection
hack and bug bounty
Ticket Fraud Scammers - An Investigation
ZephrSec - Adventures In Information Security
Ticket Fraud Scammers - An Investigation
If you're reading this, it's a blog post that's not my regular write-up but more of an investigation and a hypothesis on the anatomy of a scam. I also put it together to raise awareness for those who read my blog and who might not be overtly technical-focused.
hack and bug bounty
LTR102 - Published Finally!
ZephrSec - Adventures In Information Security
LTR102 - Published Finally!
Hello Everyone,
This a short blog post to announce I have finally published my second book after several years of work. I have spent nearly five writing it; like my first one, it follows the path of getting into and progressing in the industry, while LTR101…
hack and bug bounty
BYODC - Bring Your Own Domain Controller
ZephrSec - Adventures In Information Security
BYODC - Bring Your Own Domain Controller
BYODC or bring your own domain controller is a post-exploitation technique and another option for performing a DCSync in a more opsec safe manner.
hack and bug bounty
Multiple Paths to Compromise An Environment
ZephrSec - Adventures In Information Security
Multiple Paths to Compromise An Environment
Attack paths and compromising systems are something we, as attackers, thrive in. Many areas of system weakness can be attacked and leveraged to gain a foothold or an upper hand within an environment.
hack and bug bounty
Burp Suite Enterprise Edition Power Tools: Unleashing the power to the command line, Python, and more
PortSwigger Blog
Burp Suite Enterprise Edition Power Tools: Unleashing the power to the command line, Python, and more
tl;dr We have released BSEEPT - Burp Suite Enterprise Edition Power Tools which: Is a command line tool to drive all aspects of the BSEE GraphQL API. Is a Python client library to allow you to easily
hack and bug bounty
Server-Side Prototype Pollution Scanner
PortSwigger Blog
Server-Side Prototype Pollution Scanner
We recently published some research on server-side prototype pollution where we went into detail on techniques for detecting this vulnerability black-box. To make your life easier, we've integrated th
hack and bug bounty
Burp Suite roadmap update: January 2023
PortSwigger Blog
Burp Suite roadmap update: January 2023
The roadmap shown here is out of date. Please see our July 2023 roadmap update. Believe it or not, it's January once again. And this can mean only one thing - it's time to update you on the changes we
hack and bug bounty
Packetlabs Ltd delivers advanced testing capabilities with Burp Suite Certified Practitioners
PortSwigger Blog
Packetlabs Ltd delivers advanced testing capabilities with Burp Suite Certified Practitioners
We launched the Burp Suite Certified Practitioner (BSCP) certification at the end of 2021 due to growing demand from Burp Suite Professional customers. Spanning everything from classic vulnerability c
hack and bug bounty
Browser powered scanning 2.0
PortSwigger Blog
Browser powered scanning 2.0
It's been two years since we unleashed browser powered scanning on the world, and we decided what better way to celebrate than to start again from scratch! It started out as a task, how did it end up
hack and bug bounty
New Burp Suite API: we want your feedback!
PortSwigger Blog
New Burp Suite API: we want your feedback!
If you follow the Burp Suite roadmap, then you'll know that we're working on a complete rewrite of the "Wiener" API used in Burp Suite Professional and Burp Suite Community Edition. The new API is cod
hack and bug bounty
The Burp challenge
PortSwigger Blog
The Burp challenge
We recently launched the Burp challenge, to give our customers a unique opportunity to demonstrate their skills with Burp Suite Professional. Not only that, but the challenges involved put your web vu