Category: Mix

Buy me a coffee
23
Aug
2023

RCE in Slanger, a Ruby implementation of Pusher – honoki

While researching a web application last February, I learned about Slanger, an open source server implementation of Pusher. In this…

Bug Bytes #208 – Burp gets an update, Sharefile gets a CVE and JavaScript files get analysed
23
Aug
2023

Bug Bytes #209 – The only graphQL wordlist you need, ML bug hunting and VDP submissions

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by…

I’ve Got You Under My Skin, Bill Evans Solo Transcription – honoki
23
Aug
2023

I’ve Got You Under My Skin, Bill Evans Solo Transcription – honoki

Download my transcription of Bill Evans’ piano solo in I’ve Got You Under My Skin below. The solo starts around…

Burp ♥ OpenVPN – honoki
23
Aug
2023

Burp ♥ OpenVPN – honoki

When performing security tests, you will often be required to send all of your traffic through a VPN. If you…

architectuur, balkon, brandtrap
23
Aug
2023

XXE-scape through the front door: circumventing the firewall with HTTP request smuggling

In this write-up, I want to share a cool way in which I was able to bypass firewall limitations that…

how I bruteforced my way into your Active Directory – honoki
23
Aug
2023

how I bruteforced my way into your Active Directory – honoki

Last May, I discovered that a critical vulnerability I had reported earlier this year had resulted in my first CVE….

yet another Bug Bounty Reconnaissance Framework – honoki
23
Aug
2023

yet another Bug Bounty Reconnaissance Framework – honoki

An example use case of bbrf, here integrating with subfinder from projectdiscovery.io Like anyone involved in bug bounty hunting, I…

WILSON Cloud Respwnder – honoki
22
Aug
2023

WILSON Cloud Respwnder – honoki

If you’re a Burp Suite user, you’ll be familiar with Burp Collaborator: a service that allows you to monitor out-of-band…

Axel Springer National Media & Tech launches a public bug bounty program on Intigriti
22
Aug
2023

Axel Springer National Media & Tech launches a public bug bounty program on Intigriti

Axel Springer has long been a pioneer in the digital publishing industry, with a vast portfolio of brands, such as…

Take Care of Orphan APIs with Wallarm
21
Aug
2023

Take Care of Orphan APIs with Wallarm

The Wallarm API Discovery module has been further enhanced to enable customers to identify Orphan APIs and bring them under…

ATHI — An AI Threat Modeling Framework for Policymakers
20
Aug
2023

ATHI — An AI Threat Modeling Framework for Policymakers

My whole career has been in Information Security, and I began thinking a lot about AI in 2015. Since then…

API4:2023 Unrestricted Resource Consumption
19
Aug
2023

API4:2023 Unrestricted Resource Consumption

Welcome to the 5th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…