Title: How I Bypassed WAF on a Critical Indian Government Portal (CBSE) as a 9th-Grade Student
https://medium.com/@ujjwalanarwade945/title-how-i-bypassed-waf-on-a-critical-indian-government-portal-cbse-as-a-9th-grade-student-cc64eb78a4d0?source=rss------bug_bounty-5
https://medium.com/@ujjwalanarwade945/title-how-i-bypassed-waf-on-a-critical-indian-government-portal-cbse-as-a-9th-grade-student-cc64eb78a4d0?source=rss------bug_bounty-5
Introduction: Breaking the Stereotype “You need an English-medium background to succeed in cybersecurity.” I’ve heard this stereotype a…Continue reading on Medium » (https://medium.com/@ujjwalanarwade945/title-how-i-bypassed-waf-on-a-critical-indian-government-portal-cbse-as-a-9th-grade-student-cc64eb78a4d0?source=rss------bug_bounty-5)
A Newsletter Confirmation Link That Doubled as a Permanent, Non-Expiring Login Token
https://medium.com/@northsidehacker/a-newsletter-confirmation-link-that-doubled-as-a-permanent-non-expiring-login-token-7bb7e424d0dc?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://medium.com/@northsidehacker/a-newsletter-confirmation-link-that-doubled-as-a-permanent-non-expiring-login-token-7bb7e424d0dc?source=rss------bug_bounty-5)
https://medium.com/@northsidehacker/a-newsletter-confirmation-link-that-doubled-as-a-permanent-non-expiring-login-token-7bb7e424d0dc?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://medium.com/@northsidehacker/a-newsletter-confirmation-link-that-doubled-as-a-permanent-non-expiring-login-token-7bb7e424d0dc?source=rss------bug_bounty-5)
Workflow Bypass Leading to Unauthorized Access to Sensitive Records (IDOR / Broken Object-Level…
https://medium.com/@kaisec42/workflow-bypass-leading-to-unauthorized-access-to-sensitive-records-idor-broken-object-level-39bc801663e7?source=rss------bug_bounty-5
## SummaryContinue reading on Medium » (https://medium.com/@kaisec42/workflow-bypass-leading-to-unauthorized-access-to-sensitive-records-idor-broken-object-level-39bc801663e7?source=rss------bug_bounty-5)
https://medium.com/@kaisec42/workflow-bypass-leading-to-unauthorized-access-to-sensitive-records-idor-broken-object-level-39bc801663e7?source=rss------bug_bounty-5
## SummaryContinue reading on Medium » (https://medium.com/@kaisec42/workflow-bypass-leading-to-unauthorized-access-to-sensitive-records-idor-broken-object-level-39bc801663e7?source=rss------bug_bounty-5)
Workflow Bypass Leading to Unauthorized Access to Sensitive Records (IDOR / Broken Object-Level…
SummaryContinue reading on Medium »
Read more...
SummaryContinue reading on Medium »
Read more...
Medium
Workflow Bypass Leading to Unauthorized Access to Sensitive Records (IDOR / Broken Object-Level…
Summary
Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium »
Read more...
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium »
Read more...
Medium
Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…
One Number Was All It TookContinue reading on Medium » (https://medium.com/@abdelrahman.maged.cg/it-was-just-a-number-6547f360a1b2?source=rss------bug_bounty-5)
Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5
https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium » (https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5)
Password Reset Vulnerabilities List
https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5
https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5)
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fixContinue reading on Medium »
Read more...
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fixContinue reading on Medium »
Read more...
Medium
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fix
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matterContinue reading on Medium »
Read more...
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matterContinue reading on Medium »
Read more...
Medium
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matter