Forwarded from The Bug Bounty Hunter
How I was able to take over any users account with host header injection
https://medium.com/nassec-cybersecurity-writeups/how-i-was-able-to-take-over-any-users-account-with-host-header-injection-546fff6d0f2
https://medium.com/nassec-cybersecurity-writeups/how-i-was-able-to-take-over-any-users-account-with-host-header-injection-546fff6d0f2
Medium
How I was able to take over any users account with host header injection
Host-Header Injection is a vulnerability where a remote attacker can exploit a HTTP Host header sent by sending a fake host instead of…
Los peligros de contratar un DDoS de alquiler para hackear servidores. https://blog.ehcgroup.io/index.php/2020/01/23/los-peligros-de-contratar-un-ddos-de-alquiler-para-hackear-servidores/
blog.ehcgroup.io
Los peligros de contratar un DDoS de alquiler para hackear servidores.
Estos servicios DDoS de alquiler te ofrecen acceso a botnets orientados a ejecutar ataques, justamente, ataques distribuidos de denegación de servicio (DDoS). Recordemos que una botnet es una red de dispositivos infectados con instrucciones específicas de…
Forwarded from The Bug Bounty Hunter
Tool Release – Collaborator++
https://research.nccgroup.com/2020/01/28/tool-release-collaborator/
https://research.nccgroup.com/2020/01/28/tool-release-collaborator/
NCC Group Research Blog
Tool Release – Collaborator++
When testing for out-of-band vulnerabilities, Collaborator has been an invaluable tool since its initial release in 2015. By acting as a HTTP, DNS and SMTP server, Collaborator allows researchers t…
El FBI lanzó hoy un cartel de búsqueda de Yanqing Ye. Los fiscales federales acusan al investigador de Boston de ser realmente un teniente del ejército chino que investigó proyectos de defensa de los Estados Unidos y recopiló información sobre dos científicos estadounidenses para Beijing. Se desconoce su paradero, pero se cree que huyó a China. (FBI)
Forwarded from The Bug Bounty Hunter
Dropbox bug bounty program has paid out over $1,000,000
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/
https://blogs.dropbox.com/tech/2020/02/dropbox-bug-bounty-program-has-paid-out-over-1000000/