Category: Mix

Exploiting Null Byte Buffer Overflow for a ,000 bounty
31
Mar
2023

Exploiting Null Byte Buffer Overflow for a ,000 bounty

As a preface, when I originally found this bug I was unfamiliar the class of “null byte buffer overflow” even…

ropnop blog
30
Mar
2023

Thotcon 2018 – Fun With LDAP, Kerberos (and MSRPC) in AD Environments

Slides Supplemental The original (large) PowerPoint wih all embedded GIFs/Videos: https://1drv.ms/p/s!Aq5mEA03Lijrg9h-hsezBkUC5qwXag Source link

One More Thing to Check for SSO – Flickr ATO – Ron Chan
30
Mar
2023

One More Thing to Check for SSO – Flickr ATO – Ron Chan

I have something that is worth sharing when you are testing for SSO system. Hope you can learn something new…

No BS Guide - ADVANCED BURP (FREE) TRICKS FOR BUG BOUNTY
30
Mar
2023

No BS Guide – ADVANCED BURP (FREE) TRICKS FOR BUG BOUNTY

No BS Guide – ADVANCED BURP (FREE) TRICKS FOR BUG BOUNTY Source link

Payment bypass via parameter tampering
30
Mar
2023

Payment bypass via parameter tampering

I was recently testing a checkout payment system. It was the type of setup where everything seemed to be locked…

How to get setup to create awesome AI art · rez0
30
Mar
2023

How to get setup to create awesome AI art · rez0

Generating hacker art via AI has been a passion of mine for a few months. I was accepted into DALL·E…

Finding DOMXSS with DevTools | Untrusted Types Chrome Extension
30
Mar
2023

Finding DOMXSS with DevTools | Untrusted Types Chrome Extension

Finding DOMXSS with DevTools | Untrusted Types Chrome Extension Source link

About a Sucuri RCE…and How Not to Handle Bug Bounty Reports – RCE Security
30
Mar
2023

About a Sucuri RCE…and How Not to Handle Bug Bounty Reports – RCE Security

TL;DR Sucuri is a self-proclaimed “most recommended website security service among web professionals” offering protection, monitoring and malware removal services….

Broken Access Control - Lab #9 UID controlled by param with data leakage in redirect | Short Version
30
Mar
2023

Broken Access Control – Lab #9 UID controlled by param with data leakage in redirect | Long Version

Broken Access Control – Lab #9 UID controlled by param with data leakage in redirect | Long Version Source link

Why you should Close Your Files | bin 0x02
30
Mar
2023

Why you should Close Your Files | bin 0x02

Why you should Close Your Files | bin 0x02 Source link

SSRF AWS Metadata
30
Mar
2023

SSRF Through PDF Generation

This week on a BugBounty program which I left aside I found my first SSRF, here is my writeup. Recon…

New Burp Suite API: we want your feedback! | Blog
30
Mar
2023

New Burp Suite API: we want your feedback! | Blog

Sean Burns | 08 December 2022 at 10:45 UTC If you follow the Burp Suite roadmap, then you’ll know that…