Information Security
@sec_nerd_en
421
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
421 subscribers
Information Security
https://medium.com/@bilalmerokhel/chained-bugs-account-takeover-ceff67d1d55a
Medium
Chained Bugs [ Account TakeOver ]
Assalam-O-Alaikum fellas hope you all are fine, it has been a while I've not contributed to the community so, today I will share chained…
Information Security
https://twitter.com/PascalSec/status/1261703706464202753
Twitter
Pascal S
Just learned today that you can actually end a SQL query with "\G" as in e.g. "SELECT * FROM yourAwesomeTable \G"
🤯
Try it out and don't be shocked by what you will find
🧐
😅
#sql #magic
Information Security
https://ardern.io/2019/06/20/payload-bxss/
Information Security
“Exploiting PHP deserialization” by Vickie Li
https://link.medium.com/nrxP3xw5z6
Medium
Exploiting PHP deserialization
Intro to PHP object injection vulnerabilities
Information Security
https://doddsecurity.com/312/xml-external-entity-injection-xxe-in-opencats-applicant-tracking-system/
Dodd Security
XML External Entity Injection (XXE) in OpenCats Applicant Tracking System - Dodd Security
Vendor’s Vulnerability Announcement CVE-2019-13358 Internet Facing OpenCats: Google Dork OpenCats is an open-sourced applicant tracking system that is used to track job applicants. Versions before 0.9.4-3 suffer from a XML External Entity Injection vulnerability…
Information Security
https://labs.integrity.pt/articles/xxe-all-the-things-including-apple-ioss-office-viewer/index.html
Information Security
https://www.sans.org/blog/exploiting-xxe-vulnerabilities-in-iis-net/
www.sans.org
SANS Penetration Testing | Exploiting XXE Vulnerabilities in IIS/.NET | SANS Institute
SANS Penetration Testing blog pertaining to Exploiting XXE Vulnerabilities in IIS/.NET
Information Security
https://doddsecurity.com/94/remote-code-execution-in-the-avatars/
Dodd Security
Remote Code Execution in the Avatars - Dodd Security
Name: PHP Login & User Management Vendor: Jigowatt via the Envato Market Place Vulnerability: Arbitrary File Upload Affected Versions: All versions before 4.1.1 CVE ID: CVE-2018-11392 It goes without saying, but all user-input should not be trusted. This…
Information Security
https://gist.githubusercontent.com/harisec/519dc6b45c6b594908c37d9ac19edbc3/raw/af521a3c730d4a77660e91ed41f51725cb0bbde3/exploit_path_traversals_in_Java_webapps.txt
Information Security
https://github.com/ohjeongwook/windbgtool/blob/master/windbgtool/windows_api.json
GitHub
ohjeongwook/windbgtool
Windbg Utility Tools based upon PyKD. Contribute to ohjeongwook/windbgtool development by creating an account on GitHub.
Information Security
https://telekomsecurity.github.io/2020/05/smuggling-http-headers-through-reverse-proxies.html
Information Security
https://twitter.com/jdksec/status/1263041062450475008
Twitter
jdksec
CloudFront bypass: Worked on a public program today ">%0D%0A%0D%0A<x '="foo"><x foo='><img src=x onerror=javascript:alert(`cloudfrontbypass`)//'> Would be interested to know if this is target specific or other CloudFront websites are vulnerable #bugbountytip…
Information Security
https://maustin.net/articles/2010-07/facebook_html5
maustin.net
maustin.net | Facebook XSS via Cross-Origin Resource Sharing
HTML 5 does not do much to solve browser security issues. In fact it actually broadens the scope of what can be exploited, and forces developers to fix code ...
Information Security
https://nareshlamgade.com.np/2016/03/sql-injection-on-mega/
Naresh LamGade
SQL Injection On MEGA.NZ - Naresh LamGade
While checking Detectify Lab, I came across XSS Vulnerability on MEGA.CO.NZ which was found by Frans Rosen so I though of doing some test on MEGA but I ended with none. I didn’t give up ! after a while I thought of scanning & looking into sub domain…
Information Security
https://medium.com/sud0root/bug-bounty-writeups-exploiting-sql-injection-vulnerability-20b019553716
Medium
[Bug Bounty Writeups] Exploiting SQL Injection Vulnerability
I’m going to share this concise writeup for a bug reported to one of bug bounty programs on hackerone
Information Security
https://portswigger.net/research/documenting-the-impossible-unexploitable-xss-labs
PortSwigger Research
Documenting the impossible: Unexploitable XSS labs
Have you ever found some risky behavior, but couldn't quite prove it was exploitable? Our XSS cheat sheet contains virtually every exploit technique we know of, but what should you do if you can't fin
Information Security
https://www.codeofaninja.com/2017/02/create-simple-rest-api-in-php.html
Information Security
https://gist.github.com/aancw/492581f5faed962993c71cf233d52942
Gist
Server-Side Template Injection - RCE For the Modern WebApp by James Kettle (PortSwigger).md
GitHub Gist: instantly share code, notes, and snippets.
Information Security
https://burpsuite.tips/
Information Security
https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf