Category: Mix

We want to check out your BChecks ... | Blog
03
Jul
2023

We want to check out your BChecks … | Blog

Emma Stocks | 03 July 2023 at 14:54 UTC Want to create customized scans without the hassle of learning advanced…

Patch Diffing Progress MOVEIt Transfer RCE (CVE-2023-34362) – Assetnote
30
Jun
2023

Citrix Gateway Open Redirect and XSS (CVE-2023-24488) – Assetnote

Summary URL query parameters are not adequately sanitised before they are placed into an HTTP Location header. An attacker can…

Patch Diffing Progress MOVEIt Transfer RCE (CVE-2023-34362) – Assetnote
30
Jun
2023

Reversing Citrix Gateway for XSS – Assetnote

One of the targets we looked at late last year was Citrix Gateway. Citrix Gateway is another of these “all-in-one”…

BChecks: Houston, we have a solution! | Blog
29
Jun
2023

BChecks: Houston, we have a solution! | Blog

Ollie Whitehouse | 29 June 2023 at 12:46 UTC Scripted scan checks in Burp Suite Professional are now a thing…

Major improvements to integrations - Detectify Blog
29
Jun
2023

Major improvements to integrations – Detectify Blog

Customizable integrations for today’s security team  Resolving vulnerabilities quickly depends on several factors, not least how effectively security and product…

Maximizing Performance with Wallarm Filtering Nodes in Amazon's Global Infrastructure
28
Jun
2023

Maximizing Performance with Wallarm Filtering Nodes in Amazon’s Global Infrastructure

Introduction In today’s digital landscape, ensuring the security and performance of web applications is paramount. To achieve optimal protection against…

Bug Bytes #205 - Live Hacking, AI Hacking and Helicopter Hacking
28
Jun
2023

Bug Bytes #205 – Live Hacking, AI Hacking and Helicopter Hacking

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by…

MSF Pivoting X SocksProxy
25
Jun
2023

MSF Pivoting X SocksProxy

[*] 최근에 MSF로 Pivoting 환경에서 테스팅이 필요한 경우가 있었습니다. 방법 자체는 어려운게 아니라 그냥 몸에 있는대로 진행하긴 했는데, 생각해보니 블로그에…

Introducing Integrated API Abuse Prevention to Combat Bad Bots
22
Jun
2023

Introducing Integrated API Abuse Prevention to Combat Bad Bots

In recent years there’s been a rise in “API Abuse” attacks, which includes detrimental automated behaviors such as malicious bots,…

Bug Bytes #204 – Everything You Missed From NahamCon
21
Jun
2023

Bug Bytes #204 – Everything You Missed From NahamCon

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by…

Keep it simple, Scanner | Blog
20
Jun
2023

Keep it simple, Scanner | Blog

Tom Shelton-Lefley | 20 June 2023 at 14:02 UTC There’s a running joke on the scanner development team; for the…

GCP ESPv2 Hit with Critical API Authorization Bypass CVE-2023-30845
19
Jun
2023

GCP ESPv2 Hit with Critical API Authorization Bypass CVE-2023-30845

This post delves into a very impactful JWT Authentication Bypass vulnerability (CVE-2023-30845) found in ESP-v2, an open-source service proxy that…