Category: Mix

Building in context | victoria.dev
28
Mar
2023

Building in context | victoria.dev

The best laid plans are made better by staying close to context. It’s a comedy classic – you’ve got a…

Essential Bug Bounty Books for Beginners and Pros
28
Mar
2023

Essential Bug Bounty Books for Beginners and Pros

These bug bounty hunting books come recommended by top bug bounty hunters and hackers. Most of them cover web applications,…

Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) – Assetnote
28
Mar
2023

Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) – Assetnote

TL;DR Jira is vulnerable to SSRF which requires authentication to exploit. There are multiple ways to create user accounts on…

POSTed JSON with HTTP Client
28
Mar
2023

How to configure Json.NET to create a vulnerable web API

tl;dr No, of course, you don’t want to create a vulnerable JSON API. So when using Json.NET: Don’t use another…

Binary Analysis and Debugging – allysonomalley.com
28
Mar
2023

Binary Analysis and Debugging – allysonomalley.com

This post is the 4th and final part a series giving an overview of the most useful iOS app pentesting…

GitLab - GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection
28
Mar
2023

GitLab – GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection

HackerOne bug report to GitLab: GitLab-Runner, when running on Windows with a docker executor, is vulnerable to Command Injection via…

Q4-2022 API ThreatStats™ Report
28
Mar
2023

Q4-2022 API ThreatStats™ Report

We’re pleased to present the latest quarterly review and analysis of API vulnerabilities and exploits. This time, we’re going to…

Building a secure application in five steps | Security Simplified
28
Mar
2023

Building a secure application in five steps | Security Simplified

Building a secure application in five steps | Security Simplified Source link

TomNomNom makes a digital VU meter with HTML canvas
28
Mar
2023

TomNomNom makes a digital VU meter with HTML canvas

TomNomNom makes a digital VU meter with HTML canvas Source link

[tl;dr sec] #169 - Top 10 Web Hacking Techniques of 2022, Finding Malicious Dependencies, Fearless CORS
28
Mar
2023

[tl;dr sec] #169 – Top 10 Web Hacking Techniques of 2022, Finding Malicious Dependencies, Fearless CORS

Hey there, I hope you’ve been doing well! Coffee Snobs Aficionados I’m not a big coffee person, but it seems…

I AM GIVING AWAY A CHROMEBOOK - 100k Twitter GiveAway
28
Mar
2023

I AM GIVING AWAY A CHROMEBOOK – 100k Twitter GiveAway

I AM GIVING AWAY A CHROMEBOOK – 100k Twitter GiveAway Source link

speedtest.8x8.com: Enabled Directory Listing
28
Mar
2023

speedtest.8×8.com: Enabled Directory Listing

8×8 disclosed a bug submitted by shriyanss: https://hackerone.com/reports/1825472 Source link