Reflected XSS on microsoft[.]com subdomains
<script src=”<%= ResolveUrl(“~/Script.js”) %>”></script>
/(A(%22onerror='alert%601%60'testabcd))/
https://medium.com/bugbountywriteup/reflected-xss-on-microsoft-com-subdomains-4bdfc2c716df
<script src=”<%= ResolveUrl(“~/Script.js”) %>”></script>
/(A(%22onerror='alert%601%60'testabcd))/
https://medium.com/bugbountywriteup/reflected-xss-on-microsoft-com-subdomains-4bdfc2c716df
Medium
Reflected XSS on microsoft.com subdomains
Microsoft replied that this is out of scope of their security program as well as not deemed this as a security vulnerability at all, so I…
interesting macro samples
https://app.any.run/tasks/2be858c1-ff74-44b0-bb2a-4bb5de18a443
https://app.any.run/tasks/da537699-5942-46dd-a747-76de5e99f1ed/
https://app.any.run/tasks/2be858c1-ff74-44b0-bb2a-4bb5de18a443
https://app.any.run/tasks/da537699-5942-46dd-a747-76de5e99f1ed/
app.any.run
4dd6c0a22d4b5ff8d33c8ed45c23cc23159fd7c8f6e9e19e90fce80103cbdc50.doc (MD5: 7C7386C86CFEB790FE65DC27545DA45F) - Interactive analysis…
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
Deeplink issues:
https://youtu.be/wyIx0D-M2S8
Exploitation of exported activities (OOS on some programs, nevertheless an interesting watch)
https://youtu.be/ZUikTuoCP_M
#bugbountytip #bugbounty
https://youtu.be/wyIx0D-M2S8
Exploitation of exported activities (OOS on some programs, nevertheless an interesting watch)
https://youtu.be/ZUikTuoCP_M
#bugbountytip #bugbounty
YouTube
Android Deeplinks and how to exploit them
In this video we go over what deeplinks are and ways they can be exploited. PoC examples and example reports are also reviewed.