Information Security
@sec_nerd_en
416
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
416 subscribers
Information Security
https://www.tooboat.com/?p=1657
Information Security
https://www.exploit-db.com/docs/english/46303-remote-code-execution-with-el-injection-vulnerabilities.pdf
Information Security
https://www.betterhacker.com/2018/12/rce-in-hubspot-with-el-injection-in-hubl.html?m=1
Betterhacker
RCE in Hubspot with EL injection in HubL
This is the story of how I was able to get remote code execution on Hubspot 's servers by exploiting a vulnerability in HubL expression la...
Information Security
local_dtd
#xxe
Information Security
https://medium.com/@lokeshdlk77/how-to-rotate-ip-address-in-brute-force-attack-e66407259212
Information Security
https://medium.com/@lokeshdlk77/csrf-email-confirmation-vulnerability-for-gmail-g-suite-in-facebook-5ab551a0a526
Medium
CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook
This post is about an bug that i found on Facebook which used to verify any new Gmail and G-Suite account with minimal Victim’s…
Information Security
https://www.exploit-db.com/docs/english/45374-xml-external-entity-injection---explanation-and-exploitation.pdf
Information Security
https://www.exploit-db.com/papers?author=9381#
Exploit-Db
Offensive Security’s Exploit Database Archive
Archived security papers and articles in various languages.
Information Security
https://github.com/c0ny1/xxe-lab
GitHub
GitHub - c0ny1/xxe-lab: 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo. Contribute to c0ny1/xxe-lab development by creating an account on GitHub.
Information Security
https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
Foxglovesecurity
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability.
By @breenmachine What? The most underrated, underhyped vulnerability of 2015 has recently come to my attention, and I’m about to bring it to yours. No one gave it a fancy name, there were no …
Information Security
https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/
Information Security
https://hg8.sh/posts/resolute/
hg8's Notes — My notes about infosec world. Pentest/Bug Bounty/CTF Writeups.
HackTheBox - Resolute
Resolute just retired on Hackthebox, it’s a medium difficulty Windows box. Still being a bit new to the Windows environment the enumeration process got a bit long and tedious for me at some point bu
Information Security
https://github.com/irsdl/top10webseclist
GitHub
GitHub - irsdl/top10webseclist: Top Ten Web Hacking Techniques List
Top Ten Web Hacking Techniques List. Contribute to irsdl/top10webseclist development by creating an account on GitHub.
Information Security
https://f4d3.io/xxe_wild/
h1{Error based XXE - bug bounty writeup} | f4d3
Welcome to the bourne again f4d3.io
Information Security
https://github.com/chompie1337/s8_2019_2215_poc/
GitHub
GitHub - chompie1337/s8_2019_2215_poc: PoC 2019-2215 exploit for S8/S8 active with DAC + SELinux + Knox/RKP bypass
PoC 2019-2215 exploit for S8/S8 active with DAC + SELinux + Knox/RKP bypass - chompie1337/s8_2019_2215_poc
Information Security
https://mp.weixin.qq.com/s/hJ6gn9EMKNmMOofEg3i6Iw
*translate*
Weixin Official Accounts Platform
APT的思考: CMD命令混淆高级对抗
APT 与 HW
Information Security
https://posts.specterops.io/attacking-freeipa-part-iii-finding-a-path-677405b5b95e
Medium
Attacking FreeIPA — Part III: Finding A Path
This post is Part III in a series about my experiences attacking FreeIPA. In Part I of this series, we reviewed some of the background and…
Information Security
http://www.hexacorn.com/blog/2020/05/31/fridatrace-quick-dirty-api-monitor/
Information Security
https://github.com/tylerha97/awesome-reversing
GitHub
GitHub - tylerha97/awesome-reversing: A curated list of awesome reversing resources
A curated list of awesome reversing resources. Contribute to tylerha97/awesome-reversing development by creating an account on GitHub.
Information Security
https://medium.com/@noobintheshell/htb-patents-88bfdbde4c5a
Medium
Hack The Box :: Patents
#DOCX #XXE #LFI #RCE #pwn #BOF #ROP #ret2libc