hacking: security in practice
Figuring out if a werkzeug 1.0.1 server is running in debugger mode.
Hey everyone, new to finding exploits. Currently working on a ctf that has a site that is running a wsgi server with werkzeug 1.0.1 and python 2.7 on it. I know that there is a vulnerability with running a werkzeug server with debugger enabled. How can I figure out if the debugger mode is currently enabled? Ive looked it up and have found its easiest to try and cause an internal server error, then this would show if debugger mode is enabled. How would I go about doing that?
submitted by /u/tmag97
[link] [comments]
Figuring out if a werkzeug 1.0.1 server is running in debugger mode.
Hey everyone, new to finding exploits. Currently working on a ctf that has a site that is running a wsgi server with werkzeug 1.0.1 and python 2.7 on it. I know that there is a vulnerability with running a werkzeug server with debugger enabled. How can I figure out if the debugger mode is currently enabled? Ive looked it up and have found its easiest to try and cause an internal server error, then this would show if debugger mode is enabled. How would I go about doing that?
submitted by /u/tmag97
[link] [comments]
reddit
Figuring out if a werkzeug 1.0.1 server is running in debugger mode.
Hey everyone, new to finding exploits. Currently working on a ctf that has a site that is running a wsgi server with werkzeug 1.0.1 and python 2.7...
hacking: security in practice
Not sure if this has been asked before, but how secure are React states?
I know that browser cookies are insecure and used for CSRF and stuff. What about info that are stored in React/Redux? How do hackers go about to access them, since they're gone after a refresh? And any good practice to secure it?
submitted by /u/ohlesl1e
[link] [comments]
Not sure if this has been asked before, but how secure are React states?
I know that browser cookies are insecure and used for CSRF and stuff. What about info that are stored in React/Redux? How do hackers go about to access them, since they're gone after a refresh? And any good practice to secure it?
submitted by /u/ohlesl1e
[link] [comments]
reddit
Not sure if this has been asked before, but how secure are React...
I know that browser cookies are insecure and used for CSRF and stuff. What about info that are stored in React/Redux? How do hackers go about to...
Loader shellcode that executes an ELF in-memory using an anonymous file descriptor
https://www.reddit.com/r/redteamsec/comments/pmoseh/loader_shellcode_that_executes_an_elf_inmemory/
submitted by /u/0xDangerous_bit (https://www.reddit.com/user/0xDangerous_bit)
[link] (https://gist.github.com/zznop/0117c24164ee715e750150633c7c1782) [comments] (https://www.reddit.com/r/redteamsec/comments/pmoseh/loader_shellcode_that_executes_an_elf_inmemory/)
https://www.reddit.com/r/redteamsec/comments/pmoseh/loader_shellcode_that_executes_an_elf_inmemory/
submitted by /u/0xDangerous_bit (https://www.reddit.com/user/0xDangerous_bit)
[link] (https://gist.github.com/zznop/0117c24164ee715e750150633c7c1782) [comments] (https://www.reddit.com/r/redteamsec/comments/pmoseh/loader_shellcode_that_executes_an_elf_inmemory/)
How I Found 7 XSS Vulnerabilities in Filename Reflecting
https://alimanshester.medium.com/how-i-found-7-xss-vulnerabilities-in-filename-reflecting-6347279ee82a?source=rss------bug_bounty-5
https://alimanshester.medium.com/how-i-found-7-xss-vulnerabilities-in-filename-reflecting-6347279ee82a?source=rss------bug_bounty-5
in one of HackerOne public programsContinue reading on Medium » (https://alimanshester.medium.com/how-i-found-7-xss-vulnerabilities-in-filename-reflecting-6347279ee82a?source=rss------bug_bounty-5)
hacking: security in practice
Does Kali run on Docker well? What are the drawbacks?
I’ve read that Docker is less resource intensive and that there are Kali images for it, but some old sources mentioned it lacking full functionality.
I have a weak computer and don’t like waiting on VMware, so I’m considering this as an alternative.
submitted by /u/pass-the-word
[link] [comments]
Does Kali run on Docker well? What are the drawbacks?
I’ve read that Docker is less resource intensive and that there are Kali images for it, but some old sources mentioned it lacking full functionality.
I have a weak computer and don’t like waiting on VMware, so I’m considering this as an alternative.
submitted by /u/pass-the-word
[link] [comments]
reddit
Does Kali run on Docker well? What are the drawbacks?
I’ve read that Docker is less resource intensive and that there are Kali images for it, but some old sources mentioned it lacking full...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
source
photo
RickdiouslyEasy Walkthrough
As my first VlunHub lab practice, I had chosen this machine and got the root. Here is my walkthrough and experience. Please go through this and help me become better. I would really appreciate some constructive criticism.
https://medium.com/@sarangiprateek80/rickdiouslyeasy-walkthrough-36b3b905c500
submitted by /u/psarangi112
[link] [comments]
source
photo
RickdiouslyEasy Walkthrough
As my first VlunHub lab practice, I had chosen this machine and got the root. Here is my walkthrough and experience. Please go through this and help me become better. I would really appreciate some constructive criticism.
https://medium.com/@sarangiprateek80/rickdiouslyeasy-walkthrough-36b3b905c500
submitted by /u/psarangi112
[link] [comments]
How I Found 7 XSS Vulnerabilities in Filename Reflecting
in one of HackerOne public programsContinue reading on Medium »
Read more...
in one of HackerOne public programsContinue reading on Medium »
Read more...
Exposing Millions of IRCTC Passengers' ticket details.
https://renganathanofficial.medium.com/exposing-millions-of-irctc-passengers-ticket-details-53338280fb9e?source=rss------bug_bounty-5
https://renganathanofficial.medium.com/exposing-millions-of-irctc-passengers-ticket-details-53338280fb9e?source=rss------bug_bounty-5
Hi There,Continue reading on Medium » (https://renganathanofficial.medium.com/exposing-millions-of-irctc-passengers-ticket-details-53338280fb9e?source=rss------bug_bounty-5)
Deep Web
[HELP] payment still waiting ????
i used bitcoin to buy something and it’s still on waiting payment ?
submitted by /u/OTX4life
[link] [comments]
[HELP] payment still waiting ????
i used bitcoin to buy something and it’s still on waiting payment ?
submitted by /u/OTX4life
[link] [comments]
reddit
[HELP] payment still waiting ????
i used bitcoin to buy something and it’s still on waiting payment ?
Exposing Millions of IRCTC Passengers' ticket details.
Hi There,Continue reading on InfoSec Write-ups »
Read more...
Hi There,Continue reading on InfoSec Write-ups »
Read more...