bug bounty report template https://github.com/jaikishantulswani/bb-reports-templates
GitHub
GitHub - jaikishantulswani/bb-reports-templates: My small collection of reports templates (This is a fork of orignal repo from…
My small collection of reports templates (This is a fork of orignal repo from https://github.com/gwen001/BB-datas) - jaikishantulswani/bb-reports-templates
👍1
■■■■□ CVE-2023-25194: Remote code execution flaw patched in Apache Kafka.
https://portswigger.net/daily-swig/remote-code-execution-flaw-patched-in-apache-kafka
https://portswigger.net/daily-swig/remote-code-execution-flaw-patched-in-apache-kafka
The Daily Swig | Cybersecurity news and views
Remote code execution flaw patched in Apache Kafka
Possible RCE and denial-of-service issue discovered in Kafka Connect
url/?f=etc/passwd ==> 403
encode etc/passwd as base64
url/?f=L2V0Yy9wYXNzd2Q= ==> 200
#note
you can use this trick in SQL , SSTI , XSS , LFI , Etc...
#bugbountytips #bugbountytip
Ref: Twitter
encode etc/passwd as base64
url/?f=L2V0Yy9wYXNzd2Q= ==> 200
#note
you can use this trick in SQL , SSTI , XSS , LFI , Etc...
#bugbountytips #bugbountytip
Ref: Twitter
👍3❤1
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
https://github.com/chvancooten/BugBountyScanner
https://github.com/chvancooten/BugBountyScanner
GitHub
GitHub - chvancooten/BugBountyScanner: A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use. - chvancooten/BugBountyScanner
SSRF Cross Protocol Redirect Bypass.
https://blog.doyensec.com//2023/03/16/ssrf-remediation-bypass.html
https://blog.doyensec.com//2023/03/16/ssrf-remediation-bypass.html
PHP FILTER CHAINS: FILE READ FROM ERROR-BASED ORACLE
https://www.synacktiv.com/en/publications/php-filter-chains-file-read-from-error-based-oracle.html
https://www.synacktiv.com/en/publications/php-filter-chains-file-read-from-error-based-oracle.html
Synacktiv
PHP filter chains: file read from error-based oracle