hack and bug bounty
@hack_com
21
subscribers
20.9K
links
Download Telegram
Join
hack and bug bounty
21 subscribers
hack and bug bounty
A New Attack Surface on MS Exchange Part 1 - ProxyLogon!
Orange Tsai
A New Attack Surface on MS Exchange Part 1 - ProxyLogon!
The series of A New Attack Surface on MS Exchange: A New Attack Surface on MS Exchange Part 1 - ProxyLogon! A New Attack Surface on MS Exchange Part 2 - ProxyOracle! A New Attack Surface on MS Excha
hack and bug bounty
Red Teaming 101 — Physical Access Controls
Medium
Red Teaming 101 — Physical Access Controls
Physical access controls are designed to prevent unauthorized access to secure areas directly. Examples of physical access controls…
hack and bug bounty
Useful Offensive Snippets
Medium
Useful Offensive Snippets
I will update this post regularly, I am starting with a few of my most commonly used snippets.
hack and bug bounty
SolarWinds what probably (most-likely) happened…
Medium
SolarWinds what probably (most-likely) happened…
TL;DR
hack and bug bounty
File descriptors — pwnable.kr
Medium
File descriptors — pwnable.kr
Firstly I want to say that I highly recommend https://pwnable.kr/play.php to learn exploit development, the site is full of nice and easy…
hack and bug bounty
LEVEL 01 — IO WARGAME
Medium
LEVEL 01 — IO WARGAME
Hi everyone, it’s been some time since I last posted but I was just playing IO WARGAME and decided to write some up some solutions in the…
hack and bug bounty
Days 83, 84, 85 & 86 on https://labs.p64cyber.com
Medium
Days 83, 84, 85 & 86 on https://labs.p64cyber.com
As you should know by now, this blog has moved but incase you have missed it, check back to the site daily: https://labs.p64cyber.com
hack and bug bounty
Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools
Medium
Day 82: Hunting for Vulnerabilities in Android Apps with Burp and APK Tools
https://labs.p64cyber.com/hunting-for-vulnerabilities-in-android-apps-with-burp-and-apk-tools/
hack and bug bounty
Day 80: P64 is the new Medium
Medium
Day 80: P64 is the new Medium
Today I am sharing more than one post, the new site, P64. Over time P64 will become the number one online offensive security resource, it…
hack and bug bounty
Day 80: Becoming a Version Detection Ninja with GIT
Medium
Day 80: Becoming a Version Detection Ninja with GIT
“Day 80: Becoming a Version Detection Ninja with GIT” is published by Diddy Doodat.
hack and bug bounty
Bricks Huisarts v2.3.12.94166 vulnerable to executable uploads in e-consultation send by patients
Medium
Bricks Huisarts v2.3.12.94166 vulnerable to executable uploads in e-consultation send by patients
A bug alowed executable file uploads from patients into the EHR system. A double click on the wrong file could execute malicious code.
hack and bug bounty
Misconfigured API endpoint on portal.skge.nl leaks PII data of registered healthcare providers
Medium
Misconfigured API endpoint on portal.skge.nl leaks PII data of registered healthcare providers
Two IDOR bugs leak private data on healthcare providers; their e-mail, phone and address.
hack and bug bounty
Two different IDOR bugs at mijn.VvAA.nl
Medium
Two different IDOR bugs at mijn.VvAA.nl lead to potential access to data of 130k healthcare providers; including their own cyber…
The bugs lead to potential access to data of 130k healthcare providers; including their own cyber risk insurance policy documents.
hack and bug bounty
Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees
Medium
Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?)
Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?). Escalating a XSS bug to Perl SSTI RCE. Full…
hack and bug bounty
Laravel debug mode left on at Zouikwatzeggen.nl
Medium
Laravel debug mode left on at Zouikwatzeggen.nl
Coordinated vulnerability disclosure of a bug in an application used to submit reports of improper behaviour.
hack and bug bounty
Unprotected API endpoint at HAwebsso.nl
Medium
Unprotected API endpoint at HAwebsso.nl
Background
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
hack and bug bounty
Blind SQL Injection at fasteditor.hema.com
Medium
Blind SQL Injection at fasteditor.hema.com
A full write-up that explains the discovery and exploitation of a blind SQL injection bug.
hack and bug bounty
Reflected XSS at fotoservice.hema.nl
Medium
Reflected XSS at fotoservice.hema.nl
A full write-up that learns the reader how to find reflected XSS and open redirect bugs. Hema.nl was used as an real life example.
hack and bug bounty
Stored XSS in Paytium 3.0.13 WordPress Plugin
Medium
Stored XSS in Paytium 3.0.13 WordPress Plugin
A full write up: How to find a stored XSS bug in a Wordpress plugin and create a proof of concept payload that hijacks the full…
hack and bug bounty
Email content spoofing at IKEA.com
Medium
Email content spoofing at IKEA.com
IKEA.com did not check the fields being used in one of their email forms. This resulted in the creation of fully signed phishing email.
hack and bug bounty
Security: HTTP Smuggling, Apache Traffic Server
regilero.github.io
Security: HTTP Smuggling, Apache Traffic Server | RBleug
Regilero's blog; Mostly tech things about web stuff.