POC — CVE-2024–9935 — PDF Generator Addon for Elementor Page Builder <= 1.7.5
https://medium.com/@verylazytech/poc-cve-2024-9935-pdf-generator-addon-for-elementor-page-builder-1-7-5-2c3436b95fb1?source=rss------bug_bounty-5
https://medium.com/@verylazytech/poc-cve-2024-9935-pdf-generator-addon-for-elementor-page-builder-1-7-5-2c3436b95fb1?source=rss------bug_bounty-5
✨ For the Free article click hereContinue reading on Medium » (https://medium.com/@verylazytech/poc-cve-2024-9935-pdf-generator-addon-for-elementor-page-builder-1-7-5-2c3436b95fb1?source=rss------bug_bounty-5)
Exploiting a Rate Limiting Bug in the Chat Section of a Health Application (got me $200)
https://medium.com/@awsdevops183/exploiting-a-rate-limiting-bug-in-the-chat-section-of-a-health-application-got-me-200-a06ca465707f?source=rss------bug_bounty-5
https://medium.com/@awsdevops183/exploiting-a-rate-limiting-bug-in-the-chat-section-of-a-health-application-got-me-200-a06ca465707f?source=rss------bug_bounty-5
In the world of cybersecurity, uncovering vulnerabilities that impact user privacy and service functionality is both thrilling and…Continue reading on Medium » (https://medium.com/@awsdevops183/exploiting-a-rate-limiting-bug-in-the-chat-section-of-a-health-application-got-me-200-a06ca465707f?source=rss------bug_bounty-5)
First Google Chrome v8 JIT bug bounty before Christmas .
https://vxrl.medium.com/first-google-chrome-v8-jit-bug-bounty-before-christmas-1338fb2c8255?source=rss------bug_bounty-5
https://vxrl.medium.com/first-google-chrome-v8-jit-bug-bounty-before-christmas-1338fb2c8255?source=rss------bug_bounty-5
We will discuss about the bug later, and please stay tuned. Merry Christmas to everyone.Continue reading on Medium » (https://vxrl.medium.com/first-google-chrome-v8-jit-bug-bounty-before-christmas-1338fb2c8255?source=rss------bug_bounty-5)
How i Found X-Forwarded Header Injection — Server Be Like, ‘Ab Toh Trust Issues Ho Rahe Hain!’
https://aiwolfie.medium.com/how-i-found-x-forwarded-header-injection-server-be-like-ab-toh-trust-issues-ho-rahe-hain-220e100332a3?source=rss------bug_bounty-5
https://aiwolfie.medium.com/how-i-found-x-forwarded-header-injection-server-be-like-ab-toh-trust-issues-ho-rahe-hain-220e100332a3?source=rss------bug_bounty-5
Introduction:Continue reading on Medium » (https://aiwolfie.medium.com/how-i-found-x-forwarded-header-injection-server-be-like-ab-toh-trust-issues-ho-rahe-hain-220e100332a3?source=rss------bug_bounty-5)
How i Found X-Forwarded Header Injection — Server Be Like, ‘Ab Toh Trust Issues Ho Rahe Hain!’
Introduction:Continue reading on Medium »
Read more...
Introduction:Continue reading on Medium »
Read more...
Medium
How i Found X-Forwarded Header Injection — Server Be Like, ‘Ab Toh Trust Issues Ho Rahe Hain!’ 😂
Exploiting Trust Issues: How Misconfigured X-Forwarded Headers Can Lead to Security Vulnerabilities
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug )
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium »
Read more...
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium »
Read more...
Medium
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug 😒🐱🏍 )
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………
Where to find a professional to pentest a web application?
https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/
<!-- SC_OFF -->Hi all, I've an MVP NextJS project hosted on Heroku where users are authenticated with their Google accounts. I've 25 API end points. I've only a few test users for now and before adding more users, I would like a cost-friendly professional to test the system. I basically need to be sure that users can only fetch / edit their own data. Data is encrypted in the database (AES 256 GCM) and I also need to make sure it cannot be decrypted in some way. Where do I look to find such individual please? Thanks! <!-- SC_ON --> submitted by /u/olaf13 (https://www.reddit.com/user/olaf13)
[link] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/)
https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/
<!-- SC_OFF -->Hi all, I've an MVP NextJS project hosted on Heroku where users are authenticated with their Google accounts. I've 25 API end points. I've only a few test users for now and before adding more users, I would like a cost-friendly professional to test the system. I basically need to be sure that users can only fetch / edit their own data. Data is encrypted in the database (AES 256 GCM) and I also need to make sure it cannot be decrypted in some way. Where do I look to find such individual please? Thanks! <!-- SC_ON --> submitted by /u/olaf13 (https://www.reddit.com/user/olaf13)
[link] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/)
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug )
https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5
https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium » (https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5)
Zero-Click Account Takeover Through Response Manipulation
https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5
https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5
Hi Everyone!Continue reading on Medium » (https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5)