Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
This SIMPLE vulnerability in Shopify earned a $2500 bug bounty

Don’t forget to check for user access rightsContinue reading on InfoSec Write-ups »
Read more...
How I earned $10,000 within the last 7 months — 17y/o Edition

you know that I mostly earn bounties in Cryptocurrencies and this leads to the answer → I mostly hunt on XXXXXXXXXXXXContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks

XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes A pair of vulnerabilities in Google Cloud, DevSite, and Google Play could have allowed attackers to achieve cross-site scripting (XSS) attacks, opening the door to account hijacks.The first vulnerability is a reflected XSS bug in Google DevSite. An attacker-controlled link could run JavaScript on the origins http://cloud.google.com and http://developers.google.com, meaning a malicious actor could read and modify its contents, bypassing the same-origin policy.

Researcher ‘NDevTK’, who discovered both vulnerabilities, wrote: “Due to a vulnerability in the server-side implementation of BountyThe researcher earned $3,133.70 for the DevSite issue and $5,000 for the vulnerability in Google Play.

Speaking to The Daily Swig, they said that they were “happy with the bounty”.
Trending: GitHub introduces 2FA and quality of life improvements for npm Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: portswigger.net Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-2-1-300x150.png Microsoft SQL servers hacked to steal bandwidth with proxywareJuly 29, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-1-2-300x150.png GitHub introduces 2FA and quality of life improvements for npmJuly 28, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-5-300x150.png Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused BrandsJuly 27, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/0[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacksPost Views: 29 Premium Contenthttps://www.blackhatethicalhacking.com/wp…
7/Images-for-the-News-posts-1-1-300x150.png Cisco patches dangerous bug trio in Nexus DashboardJuly 26, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post XSS vulnerabilities in Google Cloud, Google Play could lead to account hijacks first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
This SIMPLE vulnerability in Shopify earned a $2500 bug bounty

Don’t forget to check for user access rightsContinue reading on InfoSec Write-ups »
Read more...
Why this EASY vulnerability resulted in a $20,000 bug bounty from GitLab

The hidden dangers of numerical IDsContinue reading on InfoSec Write-ups »
Read more...