Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium »
Read more...
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium »
Read more...
Medium
Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…
One Number Was All It TookContinue reading on Medium » (https://medium.com/@abdelrahman.maged.cg/it-was-just-a-number-6547f360a1b2?source=rss------bug_bounty-5)
Stored XSS via SVG File Upload Leading to Account Takeover in an LMS Platform
https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5
https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5
A few days ago, I was performing a security assessment on a foreign Learning Management System (LMS) platform. The application was…Continue reading on Medium » (https://medium.com/@hossein.za68/stored-xss-via-svg-file-upload-leading-to-account-takeover-in-an-lms-platform-c3266453c9a0?source=rss------bug_bounty-5)
Password Reset Vulnerabilities List
https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5
https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5
Continue reading on Medium » (https://medium.com/@omaralgbry1/password-reset-vulnerabilities-list-2bec302886a3?source=rss------bug_bounty-5)
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fixContinue reading on Medium »
Read more...
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fixContinue reading on Medium »
Read more...
Medium
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fix
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matterContinue reading on Medium »
Read more...
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matterContinue reading on Medium »
Read more...
Medium
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
A routine read error exposed a dangerous contract mismatch with libtiff and showed why downstream defenses still matter
Room 8 Is Live: Why Server-Side Request Forgery Still Challenges Modern Security Teams
Friendly Link:Continue reading on MeetCyber »
Read more...
Friendly Link:Continue reading on MeetCyber »
Read more...
Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
How a multi-threaded Python scanner turns manual parameter testing into an automated, context-aware workflowContinue reading on Medium »
Read more...
How a multi-threaded Python scanner turns manual parameter testing into an automated, context-aware workflowContinue reading on Medium »
Read more...
Medium
Finding Reflected XSS Parameters Fast: A Deep Dive into RefleX
How a multi-threaded Python scanner turns manual parameter testing into an automated, context-aware workflow
Lab Walkthrough: Exploiting Username Enumeration via Different Responses
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Lab Walkthrough: Exploiting Username Enumeration via Different Responses
Introduction
A 65,529-Sample Lie: How a Tiny TIFF Fooled GDAL Into Asking for 16 GB
https://medium.com/@aleens09/a-65-529-sample-lie-how-a-tiny-tiff-fooled-gdal-into-asking-for-16-gb-d3be93606c3d?source=rss------bug_bounty-5
https://medium.com/@aleens09/a-65-529-sample-lie-how-a-tiny-tiff-fooled-gdal-into-asking-for-16-gb-d3be93606c3d?source=rss------bug_bounty-5
A malformed SamplesPerPixel tag reached GDAL’s GTiff driver, triggered a 16.4 GB allocation request, and led to a codec-aware upstream fixContinue reading on Medium » (https://medium.com/@aleens09/a-65-529-sample-lie-how-a-tiny-tiff-fooled-gdal-into-asking-for-16-gb-d3be93606c3d?source=rss------bug_bounty-5)
When -1 Crossed a Library Boundary: How libvips Hardened Its TIFF Loader
https://medium.com/@aleens09/when-1-crossed-a-library-boundary-how-libvips-hardened-its-tiff-loader-35cda3e16544?source=rss------bug_bounty-5
https://medium.com/@aleens09/when-1-crossed-a-library-boundary-how-libvips-hardened-its-tiff-loader-35cda3e16544?source=rss------bug_bounty-5