This media is not supported in your browser
VIEW IN TELEGRAM
Henry Chen
@chybeta
CVE-2019-8451 Unauthorized SSRF via REST API /plugins/servlet/gadgets/makeRequest
use @ to bypass the whitelisting !
https://jira.atlassian.com/browse/JRASERVER-70001?filter=13085
@chybeta
CVE-2019-8451 Unauthorized SSRF via REST API /plugins/servlet/gadgets/makeRequest
use @ to bypass the whitelisting !
https://jira.atlassian.com/browse/JRASERVER-70001?filter=13085
vb5.py
820 B
# vBulletin 5.x 0day pre-auth RCE exploit
#
# This should work on all versions from 5.0.0 till 5.5.4
#
# This should work on all versions from 5.0.0 till 5.5.4
Information Security
https://medium.com/101-writeups/hacking-json-web-token-jwt-233fe6c862e6
GitHub
GitHub - pinnace/burp-jwt-fuzzhelper-extension: JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.
JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing. - pinnace/burp-jwt-fuzzhelper-extension
bypass360mimikatz_x64:--
Method: change resources, add a digital signature
Unzip password: 6613kris
https://github.com/ianxtianxt/bypass360mimikatz_x64
Method: change resources, add a digital signature
Unzip password: 6613kris
https://github.com/ianxtianxt/bypass360mimikatz_x64
GitHub
GitHub - ianxtianxt/bypass360mimikatz_x64
Contribute to ianxtianxt/bypass360mimikatz_x64 development by creating an account on GitHub.