Facebook OAuth 2.0 Misconfiguration
Testing vuln.com for Auth Flows I found oneContinue reading on InfoSec Write-ups »
Read more...
Testing vuln.com for Auth Flows I found oneContinue reading on InfoSec Write-ups »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Biggest Hack In Crypto History Poly Network Hack - How Did It Happen? An Extensive Code Analysis
https://external-preview.redd.it/5LINEFSzjCKWccnGsBRIQDRK_MxtOXNvRkM0AOh7sj0.jpg?width=320&crop=smart&auto=webp&s=0457723081596e6f83d066269f17c3964c92e998 submitted by /u/joe691013
[link] [comments]
Biggest Hack In Crypto History Poly Network Hack - How Did It Happen? An Extensive Code Analysis
https://external-preview.redd.it/5LINEFSzjCKWccnGsBRIQDRK_MxtOXNvRkM0AOh7sj0.jpg?width=320&crop=smart&auto=webp&s=0457723081596e6f83d066269f17c3964c92e998 submitted by /u/joe691013
[link] [comments]
hacking: security in practice
Python Pickle cookie Injection
Hello everyone, I am currently researching how to get RCE by supplying malicious cookies to a webserver.
I have a session cookie thats hex encoded pickle bytestream, when decoded it shows a timestamp and a local file path for a file that is displayed on the webpage.
I tried to create arbitary cookies that include a pickle payload but the server always gives me a error 500 when i send a get request using my cookies. If i use the original cookie it works and when I parse my arbitary cookies with python my code gets executed.
So I guess that the webserver checks the pickle data some way before loading the pickle but i dont know how.
Does someone have experience with webapp pickle attacks and give me some pointers/advice?
submitted by /u/lololxd12345
[link] [comments]
Python Pickle cookie Injection
Hello everyone, I am currently researching how to get RCE by supplying malicious cookies to a webserver.
I have a session cookie thats hex encoded pickle bytestream, when decoded it shows a timestamp and a local file path for a file that is displayed on the webpage.
I tried to create arbitary cookies that include a pickle payload but the server always gives me a error 500 when i send a get request using my cookies. If i use the original cookie it works and when I parse my arbitary cookies with python my code gets executed.
So I guess that the webserver checks the pickle data some way before loading the pickle but i dont know how.
Does someone have experience with webapp pickle attacks and give me some pointers/advice?
submitted by /u/lololxd12345
[link] [comments]
reddit
Python Pickle cookie Injection
Hello everyone, I am currently researching how to get RCE by supplying malicious cookies to a webserver. I have a session cookie thats hex...
Mass Assignment — Entendendo o que é, Como explorar, Caso de estudo e Corrigindo a falha
Neste artigo falaremos sobre uma falha popular classificada como TOP 6 na OWASP TOP 10 API 2019, uma falha que permite que um atacante…Continue reading on Medium »
Read more...
Neste artigo falaremos sobre uma falha popular classificada como TOP 6 na OWASP TOP 10 API 2019, uma falha que permite que um atacante…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Semi-Structured Data Parsing and Extraction using Python
https://cdn-images-1.medium.com/max/1920/1*KHjZF_6W5D9QEryCwNHcfQ.jpeg
Use Python to extract data from semi-structured sources like PDF or Excel.
Continue reading on Medium »
Semi-Structured Data Parsing and Extraction using Python
https://cdn-images-1.medium.com/max/1920/1*KHjZF_6W5D9QEryCwNHcfQ.jpeg
Use Python to extract data from semi-structured sources like PDF or Excel.
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Neko Hacking Incident Review
Recently a new attack on the smart contract lending pools was discovered. Maze protocol team was the first who had suffered from it. We…
Continue reading on Medium »
Neko Hacking Incident Review
Recently a new attack on the smart contract lending pools was discovered. Maze protocol team was the first who had suffered from it. We…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to identify the traces of the tor browser during the investigation?
https://cdn-images-1.medium.com/max/2600/1*0Dnd9woqoHQ7qyx9mk1C6w.jpeg
Tor browser is one of the topics that excite every cybersecurity enthusiast. Tor was made for only one purpose, i.e., to make the user…
Continue reading on Medium »
How to identify the traces of the tor browser during the investigation?
https://cdn-images-1.medium.com/max/2600/1*0Dnd9woqoHQ7qyx9mk1C6w.jpeg
Tor browser is one of the topics that excite every cybersecurity enthusiast. Tor was made for only one purpose, i.e., to make the user…
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
LAB. 利用Google Hacking來踩點
https://cdn-images-1.medium.com/max/724/1*DDg3Mxf5PvG5b1wuZPwqqw.png
Perform Footprinting Through Search Engines
Continue reading on 資訊安全筆記 »
LAB. 利用Google Hacking來踩點
https://cdn-images-1.medium.com/max/724/1*DDg3Mxf5PvG5b1wuZPwqqw.png
Perform Footprinting Through Search Engines
Continue reading on 資訊安全筆記 »