Articles worth reading discovered last week:
🗞
https://research.securitum.com/css-data-exfiltration-in-firefox-via-single-injection-point/
🗞
https://blog.xpnsec.com/testing-redteam-infra/
🗞
https://blog.truesec.com/2020/02/12/from-s3-bucket-to-laravel-unserialize-rce/
🗞
https://research.securitum.com/css-data-exfiltration-in-firefox-via-single-injection-point/
🗞
https://blog.xpnsec.com/testing-redteam-infra/
🗞
https://blog.truesec.com/2020/02/12/from-s3-bucket-to-laravel-unserialize-rce/
research.securitum.com
CSS data exfiltration in Firefox via a single injection point - research.securitum.com
A few months ago I identified a security issue in Firefox known as CVE-2019-17016. During analysis of the issue, I’ve come up with a new technique of CSS data exfiltration in Firefox via a single injection point which I’m going to share in this blog post.
SAML Security Testing Tutorial:
1 - https://t.co/imIWYX6AdF
2 - https://t.co/Gz9Vg2DeoX
3 - https://t.co/RVX6m56n0W
Attack Surface: https://t.co/DIsjXQYJ06
Examples of bugs:
- https://t.co/D6aHlzTxlA
- https://t.co/YFy5SHYHL4
- https://t.co/e74Msi6a3k
#bugbounty #bugbountytip
1 - https://t.co/imIWYX6AdF
2 - https://t.co/Gz9Vg2DeoX
3 - https://t.co/RVX6m56n0W
Attack Surface: https://t.co/DIsjXQYJ06
Examples of bugs:
- https://t.co/D6aHlzTxlA
- https://t.co/YFy5SHYHL4
- https://t.co/e74Msi6a3k
#bugbounty #bugbountytip
epi052.gitlab.io
How to Hunt Bugs in SAML; a Methodology - Part I -
The first in a series of three posts about a methodology for hunting bugs in SAML. This post covers background information about SAML, laying the groundwork to understand SAML vulnerabilities and attacks.