Forwarded from The Bug Bounty Hunter
CRLF injection
https://hackerone.com/reports/446271
https://hackerone.com/reports/446271
HackerOne
X / xAI disclosed on HackerOne: CRLF injection
https://ads.twitter.com was vulnerability to HTTP response splitting in the endpoint https://ads.twitter.com/subscriptions/mobile/landing that allows to an attacker add a malicious header in the...
CVE-2019-19844: posible robo de cuenta a través de la clave de la contraseña PoC para Django
https://github.com/ryu22e/django_cve_2019_19844_poc/
Detalle:
https://ryu22e.org/posts/2019/12/23/django-cve-2019-19118/
https://github.com/ryu22e/django_cve_2019_19844_poc/
Detalle:
https://ryu22e.org/posts/2019/12/23/django-cve-2019-19118/
GitHub
GitHub - ryu22e/django_cve_2019_19844_poc: PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)
PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/) - ryu22e/django_cve_2019_19844_poc
Forwarded from The Bug Bounty Hunter
RCE with Burp Suite intruder + Regex https://www.youtube.com/watch?v=Xm77r80NxZo
YouTube
RCE with Burp Suite intruder + Regex
Detection RCE technique with Burp suite.
I am useing regex for detection vulns and errors in response.
Regex: https://github.com/ghsec/webHunt/blob/master/ErrorsAndVulnsDetect.md
Payloads: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/C…
I am useing regex for detection vulns and errors in response.
Regex: https://github.com/ghsec/webHunt/blob/master/ErrorsAndVulnsDetect.md
Payloads: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/C…
Irán cortejó al experto en seguridad de EE. UU. Durante años, buscando capacitación en piratería industrial.
https://arstechnica.com/information-technology/2020/01/iran-courted-us-security-expert-for-years-seeking-industrial-hacking-training/
https://arstechnica.com/information-technology/2020/01/iran-courted-us-security-expert-for-years-seeking-industrial-hacking-training/
Ars Technica
Iran courted US security expert for years, seeking industrial hacking training
In emails and WhatsApp messages, Iranian telecom official tried to recruit US researcher.
A quien le guste los retos, wargames, labs.. estamos creando una comunidad abierta para subir y compartir todo referente a esto:
https://u.tpx.mx/registro-comunidad
B-\ el registro quedará abierto 3 días.
Pronto más info 😛
https://u.tpx.mx/registro-comunidad
B-\ el registro quedará abierto 3 días.
Pronto más info 😛