Category: Mix

How To Start Bug Bounty For Beginners
21
Mar
2023

How To Start Bug Bounty For Beginners

So you want to be a hack super star? And live large, a big house, five cars. Let me preface…

When Static Is Not Actually Static – Assetnote
21
Mar
2023

When Static Is Not Actually Static – Assetnote

Over the last ten years, we have seen the industrialization of the content management space. A decade ago, it felt…

uploaded JSP executed on the server
21
Mar
2023

Apache Tomcat RCE if readonly set to false (CVE-2017-12617)

The Vulnerability The Apache Tomcat team announced today that all Tomcat versions before 9.0.1 (Beta), 8.5.23, 8.0.47 and 7.0.82 contain…

Exploiting SSL Vulnerabilities in Mobile Apps – allysonomalley.com
21
Mar
2023

Exploiting SSL Vulnerabilities in Mobile Apps – allysonomalley.com

This post is an overview of a mobile app MitM vulnerability I’ve found several times in the real world. I’ll…

Access to remapped root allows privilege escalation to real root · Advisory · moby/moby · GitHub
20
Mar
2023

Access to remapped root allows privilege escalation to real root · Advisory · moby/moby · GitHub

Impact When using –userns-remap, if the root user in the remapped namespace has access to the host filesystem they can…

Compromising an unreachable Solr server with CVE-2013-6397
20
Mar
2023

Compromising an unreachable Solr server with CVE-2013-6397

Compromising an unreachable Solr server with CVE-2013-6397 I recently did a pentest where I compromised a Solr server located several…

VMware NSX Manager Vulnerabilities being actively exploited
20
Mar
2023

VMware NSX Manager Vulnerabilities being actively exploited

The Wallarm Detect team has found exploit attempts in the wild of CVE-2022-31678 and CVE-2021-39144. The original vulnerabilities were found…

How to conduct a basic security code review | Security Simplified
20
Mar
2023

How to conduct a basic security code review | Security Simplified

How to conduct a basic security code review | Security Simplified Source link

Two solutions for the January 2021 Initigriti XSS Challenge
20
Mar
2023

Two solutions for the January 2021 Initigriti XSS Challenge

Two solutions for the January 2021 Initigriti XSS Challenge Source link

[tl;dr sec] #170 - Prototype Pollution, Fuzzing, SOC Metrics
20
Mar
2023

[tl;dr sec] #170 – Prototype Pollution, Fuzzing, SOC Metrics

Hey there, I hope you’ve been doing well! Focusing on the Right Stuff I was going to write you a…

Raidforums owner arrested 🚓 FBI have taken on the case 🚓
20
Mar
2023

Raidforums owner arrested 🚓 FBI have taken on the case 🚓

Raidforums owner arrested 🚓 FBI have taken on the case 🚓 Source link

CVE-2023-27537: HSTS double-free
20
Mar
2023

CVE-2023-27537: HSTS double-free

curl disclosed a bug submitted by kurohiro: https://hackerone.com/reports/1897203 Source link