hack and bug bounty
@hack_com
21
subscribers
20.9K
links
Download Telegram
Join
hack and bug bounty
21 subscribers
hack and bug bounty
Misconfigured API endpoint on portal.skge.nl leaks PII data of registered healthcare providers
Medium
Misconfigured API endpoint on portal.skge.nl leaks PII data of registered healthcare providers
Two IDOR bugs leak private data on healthcare providers; their e-mail, phone and address.
hack and bug bounty
Two different IDOR bugs at mijn.VvAA.nl
Medium
Two different IDOR bugs at mijn.VvAA.nl lead to potential access to data of 130k healthcare providers; including their own cyber…
The bugs lead to potential access to data of 130k healthcare providers; including their own cyber risk insurance policy documents.
hack and bug bounty
Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees
Medium
Remote Code execution at ws1.aholdusa.com — Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?)
Compromising logins of Ahold Delhaize USA employees for >3.5 years (or even 18 years?). Escalating a XSS bug to Perl SSTI RCE. Full…
hack and bug bounty
Laravel debug mode left on at Zouikwatzeggen.nl
Medium
Laravel debug mode left on at Zouikwatzeggen.nl
Coordinated vulnerability disclosure of a bug in an application used to submit reports of improper behaviour.
hack and bug bounty
Unprotected API endpoint at HAwebsso.nl
Medium
Unprotected API endpoint at HAwebsso.nl
Background
As some might know, I work as a medical doctor (general practitioner) by day and as a security researcher by night. One of my…
hack and bug bounty
Blind SQL Injection at fasteditor.hema.com
Medium
Blind SQL Injection at fasteditor.hema.com
A full write-up that explains the discovery and exploitation of a blind SQL injection bug.
hack and bug bounty
Reflected XSS at fotoservice.hema.nl
Medium
Reflected XSS at fotoservice.hema.nl
A full write-up that learns the reader how to find reflected XSS and open redirect bugs. Hema.nl was used as an real life example.
hack and bug bounty
Stored XSS in Paytium 3.0.13 WordPress Plugin
Medium
Stored XSS in Paytium 3.0.13 WordPress Plugin
A full write up: How to find a stored XSS bug in a Wordpress plugin and create a proof of concept payload that hijacks the full…
hack and bug bounty
Email content spoofing at IKEA.com
Medium
Email content spoofing at IKEA.com
IKEA.com did not check the fields being used in one of their email forms. This resulted in the creation of fully signed phishing email.
hack and bug bounty
Security: HTTP Smuggling, Apache Traffic Server
regilero.github.io
Security: HTTP Smuggling, Apache Traffic Server | RBleug
Regilero's blog; Mostly tech things about web stuff.
hack and bug bounty
BChecks: Houston, we have a solution!
PortSwigger Blog
BChecks: Houston, we have a solution!
Scripted scan checks in Burp Suite Professional are now a thing ... tl;dr Burp Suite Professional now has a powerful yet simple scripting language that allows you to quickly build on our world c
hack and bug bounty
Keep it simple, Scanner
PortSwigger Blog
Keep it simple, Scanner
There’s a running joke on the scanner development team; for the longest time I had net negative lines of code added to the Burp Suite codebase, and everyone’s convinced that I’m trying to regain that
hack and bug bounty
New: Burp Suite Enterprise Edition Pay as you scan pricing
hack and bug bounty
New: Burp Suite Enterprise Edition Unlimited pricing
hack and bug bounty
Burp Suite Enterprise Edition Power Tools: Unleashing the power to the command line, Python, and more
PortSwigger Blog
Burp Suite Enterprise Edition Power Tools: Unleashing the power to the command line, Python, and more
tl;dr We have released BSEEPT - Burp Suite Enterprise Edition Power Tools which: Is a command line tool to drive all aspects of the BSEE GraphQL API. Is a Python client library to allow you to easily
hack and bug bounty
Server-Side Prototype Pollution Scanner
PortSwigger Blog
Server-Side Prototype Pollution Scanner
We recently published some research on server-side prototype pollution where we went into detail on techniques for detecting this vulnerability black-box. To make your life easier, we've integrated th
hack and bug bounty
Burp Suite roadmap update: January 2023
PortSwigger Blog
Burp Suite roadmap update: January 2023
The roadmap shown here is out of date. Please see our July 2023 roadmap update. Believe it or not, it's January once again. And this can mean only one thing - it's time to update you on the changes we
hack and bug bounty
Packetlabs Ltd delivers advanced testing capabilities with Burp Suite Certified Practitioners
PortSwigger Blog
Packetlabs Ltd delivers advanced testing capabilities with Burp Suite Certified Practitioners
We launched the Burp Suite Certified Practitioner (BSCP) certification at the end of 2021 due to growing demand from Burp Suite Professional customers. Spanning everything from classic vulnerability c
hack and bug bounty
Browser powered scanning 2.0
PortSwigger Blog
Browser powered scanning 2.0
It's been two years since we unleashed browser powered scanning on the world, and we decided what better way to celebrate than to start again from scratch! It started out as a task, how did it end up
hack and bug bounty
New Burp Suite API: we want your feedback!
PortSwigger Blog
New Burp Suite API: we want your feedback!
If you follow the Burp Suite roadmap, then you'll know that we're working on a complete rewrite of the "Wiener" API used in Burp Suite Professional and Burp Suite Community Edition. The new API is cod