Category: Mix

mert tasci
06
Jan
2024

parameter pollution bug at twitter | by mert tasci

mert tasci · Follow 1 min read · Mar 11, 2023 — 1 Listen Share twitter sent an e-mail to…

Piercing the Veal: Short Stories to Read with Friends | by d0nut
06
Jan
2024

Piercing the Veal: Short Stories to Read with Friends | by d0nut

This feedback mechanism made me realize that this was more than a simple CRUD app and this service must be…

mert tasci
06
Jan
2024

a little open redirect bypass story | by mert tasci

in one private program at bugcrowd, i came across three different open redirect bug methods. firstthis is an effortless open…

My Year in Review — 2020. So | by d0nut
06
Jan
2024

My Year in Review — 2020. So | by d0nut

While terribly disappointed, I still had drive left in me to do well for myself and continue onward. At this…

[tl;dr sec] #212 - AWS Security Services Best Practices, EDR Bypass Lab, 100+ Vulnerable Practice Apps
06
Jan
2024

[tl;dr sec] #212 – AWS Security Services Best Practices, EDR Bypass Lab, 100+ Vulnerable Practice Apps

I hope you’ve been doing well! 👋 New Year, Who Dis? I hope you had a great holiday break and…

mert tasci
06
Jan
2024

xss attack vector at “style” context for less.js – mert tasci

detailless & sass suddenly came to my mind when researching about of css injection attacks. you know, both are css…

The Stony Path of Android 🤖 Bug Bounty – Bypassing Certificate Pinning
06
Jan
2024

The Stony Path of Android 🤖 Bug Bounty – Bypassing Certificate Pinning

Dear readers, Long story short, doing bug bounties for mobile devices is hard. With this article I want to show…

Alyssa Herrera
06
Jan
2024

High Risk Vulnerabilities within the DoD – Exploiting Coldfusion, Dotnet Nuke, Oracle, and more | by Alyssa Herrera

The Department of Defense Launched a bug bounty program on November 21st, 2016 on Hackerone. This allowed researchers to report…

BugBountyHunter Chats — Getting to know 0xblackbird, YouGina, JTCSec and HolyBugx | by Sean (zseano)
06
Jan
2024

BugBountyHunter Chats — Getting to know 0xblackbird, YouGina, JTCSec and HolyBugx | by Sean (zseano)

18 min read · Jul 12, 2021 BugBountyHunter.com opened early November 2020 and the amount of growth we have seen…

Addressing the Rising Threat of API Leaks
03
Jan
2024

Addressing the Rising Threat of API Leaks

In the realm of cybersecurity, the metaphor of “Leaky Buckets” has become an increasingly prevalent concern, particularly in the context…

7 Things to Expect from AI in 2024+, Xi Going Stalin, SSH's Terrapin…
02
Jan
2024

7 Things to Expect from AI in 2024+, Xi Going Stalin, SSH’s Terrapin…

Unsupervised Learning is a Security, AI, and Meaning-focused podcast that looks at how best to thrive as humans in a…

Cory Doctorow is Not Even Wrong About the So-called "AI Bubble"
02
Jan
2024

Cory Doctorow is Not Even Wrong About the So-called “AI Bubble”

I’ve had to make rule for my events: The first person to mention AI owes everyone else a drink. It’s…