Category: Mix

From Quiz to Admin – Chaining Two 0-Days to Compromise An Uber WordPress – RCE Security
27
Mar
2023

From Quiz to Admin – Chaining Two 0-Days to Compromise An Uber WordPress – RCE Security

TL;DR While doing recon for H1-4420, I stumbled upon a WordPress blog that had a plugin enabled called SlickQuiz. Although…

Broken Access Control - Lab #9 UID controlled by param with data leakage in redirect | Short Version
27
Mar
2023

Broken Access Control – Lab #9 UID controlled by param with data leakage in redirect | Short Version

Broken Access Control – Lab #9 UID controlled by param with data leakage in redirect | Short Version Source link

This Website has No Code, or Does it?
26
Mar
2023

This Website has No Code, or Does it?

This Website has No Code, or Does it? Source link

GAU recon
26
Mar
2023

Basic recon to RCE

Recently on a BugBounty program I came across my first RCE, discovered and exploited rather quickly on a solution with…

Browser powered scanning 2.0 | Blog
26
Mar
2023

Browser powered scanning 2.0 | Blog

Tom Shelton-Lefley | 15 December 2022 at 14:30 UTC It’s been two years since we unleashed browser powered scanning on…

How to Hunt for Prototype Pollution Vulnerabilities in Open Source Bug Bounty | #methodology
26
Mar
2023

How to Hunt for Prototype Pollution Vulnerabilities in Open Source Bug Bounty | #methodology

How to Hunt for Prototype Pollution Vulnerabilities in Open Source Bug Bounty | #methodology Source link

#NahamCon2022EU: Managing a Bug Bounty Program From a Hacker's Perspective by @0xlupin
26
Mar
2023

#NahamCon2022EU: Managing a Bug Bounty Program From a Hacker’s Perspective by @0xlupin

#NahamCon2022EU: Managing a Bug Bounty Program From a Hacker’s Perspective by @0xlupin Source link

Hack the Box: How does linux work?
26
Mar
2023

Hack the Box: How does linux work?

Hack the Box: How does linux work? Source link

Stream 00 : How to Bypass WAF for your XSS ! (OSINT Bonus) 🔥
26
Mar
2023

Stream 00 : How to Bypass WAF for your XSS ! (OSINT Bonus) 🔥

Stream 00 : How to Bypass WAF for your XSS ! (OSINT Bonus) 🔥 Source link

Velocity Exploit on Paper?
26
Mar
2023

Velocity Exploit on Paper?

Velocity Exploit on Paper? Source link

Here's how you can become member of my website.
26
Mar
2023

Here’s how you can become member of my website.

My blog runs on Ghost. For some time it has a members feature. Last week I decided to enable it…

So Linus Tech Tips Got Hacked...
26
Mar
2023

So Linus Tech Tips Got Hacked…

So Linus Tech Tips Got Hacked… Source link