Password reset flaw
https://t.co/jGpEwy3Lpt
https://t.co/Cq3rHAIid1
https://t.co/OJiiXUZgWS
https://t.co/rJGr1hRtlw
https://t.co/1aYPhHoW2U
https://t.co/ufBZWGwptT
https://t.co/t3HFbNtXa5
https://t.co/i1PQ79EJHA
https://t.co/uY7UkHi2Mf
https://t.co/LpkUySCXf1
#bugbounty
https://t.co/jGpEwy3Lpt
https://t.co/Cq3rHAIid1
https://t.co/OJiiXUZgWS
https://t.co/rJGr1hRtlw
https://t.co/1aYPhHoW2U
https://t.co/ufBZWGwptT
https://t.co/t3HFbNtXa5
https://t.co/i1PQ79EJHA
https://t.co/uY7UkHi2Mf
https://t.co/LpkUySCXf1
#bugbounty
Medium
How I discovered an interesting account takeover flaw?
Hi everyone, today I will talk about an interesting account takeover flaw which I found around a year back. The root cause of this issue…
#CSRF
https://t.co/EVShJTsIP6
https://t.co/vB1z8VL0j1
https://t.co/Z8mMOnM8Co
https://t.co/eL6yL9z5ZZ
https://t.co/i1NsI8MeB7
https://t.co/RhplucOSlq
https://t.co/EwIONkbC0k
https://t.co/PTxDhMLmS7
https://t.co/kWrLyNB8fH
https://t.co/2PLIzQsPIZ
#bugbounty #bugbountytips
https://t.co/EVShJTsIP6
https://t.co/vB1z8VL0j1
https://t.co/Z8mMOnM8Co
https://t.co/eL6yL9z5ZZ
https://t.co/i1NsI8MeB7
https://t.co/RhplucOSlq
https://t.co/EwIONkbC0k
https://t.co/PTxDhMLmS7
https://t.co/kWrLyNB8fH
https://t.co/2PLIzQsPIZ
#bugbounty #bugbountytips
santuySec
Google Bug Bounty: CSRF in learndigital.withgoogle.com - santuySec
Hi everyone,This is my first Google bug bounty writeups, I want to tell you about CSRF vulnerability on Google Digital Garage. Have you ever heard of the Google Gigital Garage? an online courses from Google that is designed for you to grow your career or…
This media is not supported in your browser
VIEW IN TELEGRAM
CVE-2020-7799 FusionAuth RCE via Apache Freemarker Template
This media is not supported in your browser
VIEW IN TELEGRAM
SettingSyncHost.exe as a LolBin
http://hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/
#LOLBIN
cd %TEMP% & c:\windows\system32\SettingSyncHost.exe -LoadAndRunDiagScript foo
http://hexacorn.com/blog/2020/02/02/settingsynchost-exe-as-a-lolbin/
#LOLBIN
cd %TEMP% & c:\windows\system32\SettingSyncHost.exe -LoadAndRunDiagScript foo
Buffer overflow in sudo versions 1.7.1 - 1.8.25p1 when pwfeedback is set in sudoers
https://www.sudo.ws/alerts/pwfeedback.html
https://www.sudo.ws/alerts/pwfeedback.html
Sudo
Buffer overflow when pwfeedback is set in sudoers
Sudo’s pwfeedback option can be used to provide visual feedback when the user is inputting their password. For each key press, an asterisk is printed. This option was added in response to user confusion over how the standard Password: prompt disables the…
XSS filter bypass using stripped </p> tag to obfuscate.
P2 Stored XSS $1500 on a private bug bounty program.
XSS Payload:
<</p>iframe src=javascript:alert()//
P2 Stored XSS $1500 on a private bug bounty program.
XSS Payload:
<</p>iframe src=javascript:alert()//