tpx Security ⠠⠵
2.4K subscribers
2.31K photos
103 videos
24 files
3.97K links
Hacking, ciberseguridad e Inteligencia.
Download Telegram
Buen Viernes !
Exfiltration through FTP using OOB XXE

Upload accepts .xlsx files --> Unzip sample .xlsx file -> add payload in workbook.xml/[Content_Types].xml after xml declaration --> DTD file send data via ftp://remote-ip/%data --> run ftp server using xxe-ftp-server.rb --> /etc/passwd

Via: https://twitter.com/_ayoubfathi_/status/1164536885244583941
jsonp is a Burp Extension which attempts to reveal JSONP functionality behind JSON endpoints. This could help reveal cross-site script inclusion vulnerabilities or aid in bypassing content security policies.
https://github.com/kapytein/jsonp
#EnVivo Presentación del documento “Estado de la #ciberseguridad en el sistema financiero en México 🇲🇽 ”, a cargo de
@belisarioc, Gerente del Programa de Ciberseguridad, @OEA_Cyber
🎥 https://youtu.be/4eVuKnpi0IE
DragonJarCon - El lado excitante de IoT; Pentestig de sex toys 💦
Happy Birthday HACKERS

9/15/95
Adiós 👋🏼 RMS