Category: Mix
Recording Slides Source link
Uber is built on a bunch of microservices, naturally, if you want to interact with microservice, you may want to…
INTERVIEW w @SherlockSecure : TOP 15 on GITHUB | TOP 400 on BC | APPROACH, MINDSET & MORE… Source link
Introduction This write-up is about hacking the Razer Pay Android app – an E-Wallet app used in Singapore and Malaysia….
I’ve been using ChatGPT for lots of hacking or engineering tasks. It’s extremely useful and much faster than executing on…
Automating Permission Checks Using OpenAPI Security Scanner? Source link
This is a review of the Advanced Web Attacks and Exploitation (WEB-300) course and its OSWE exam by Offensive-Security. I’ve…
Broken Access Control – Lab #7 User ID controlled by request parameter | Long Version Source link
Dangerous Code Hidden in Plain Sight for 12 years Source link
The Story [EDIT 26/04/22] – I added a note on my personal conclusion about Amass with a note from a…
Gareth Heyes | 13 March 2023 at 15:00 UTC We recently published some research on server-side prototype pollution where we…
tldr; A Private Bug Bounty Program had a globally readable .htpasswd file. I cracked the DES hash, got access to…