Category: Mix

The Best Bug Bounty Recon Methodology
24
Mar
2023

The Best Bug Bounty Recon Methodology

My first introduction to reconnaissance was Jason Haddix’s Bug Bounty Hunters Methodology. It’s the de facto standard and is still…

Pre Auth Remote Command Execution (CVE-2022-36804) – Assetnote
24
Mar
2023

Pre Auth Remote Command Execution (CVE-2022-36804) – Assetnote

Often when performing application security research, we come across other researchers who have found critical vulnerabilities in software that can…

JSF based login
24
Mar
2023

Misconfigured JSF ViewStates can lead to severe RCE vulnerabilities

tl;dr ViewStates in JSF are serialized Java objects. If the used JSF implementation in a web application is not configured…

Seguridad de iOS – Web View XSS – allysonomalley.com
24
Mar
2023

Seguridad de iOS – Web View XSS – allysonomalley.com

Esta entrada se trata de una vulnerabilidad sencilla, pero peligrosa, que he visto en varias ocasiones. Creo que esta falla…

community/KCSA-CVE-2020-28914.md at main · kata-containers/community · GitHub
24
Mar
2023

community/KCSA-CVE-2020-28914.md at main · kata-containers/community · GitHub

announcement-date: 2020-11-17 id: KCSA-CVE-2020-28914 title: Kata Containers Improper file permissions for read-only volumes description: An improper file permissions vulnerability affects…

Exploiting WPAD with Burp Suite and the "HTTP Injector" extension | Agarri : Sécurité informatique offensive
24
Mar
2023

Exploiting WPAD with Burp Suite and the “HTTP Injector” extension | Agarri : Sécurité informatique offensive

Exploiting WPAD with Burp Suite and the “HTTP Injector” extension I went last week to the ASFWS conference (“Application Security…

Insights into the New OWASP API Security Top-10 for CISOs
24
Mar
2023

Insights into the New OWASP API Security Top-10 for CISOs

ICYMI, we recently presented A CISOs Guide to the New 2023 OWASP API Security Update. In this first of two…

Launching an InfoSec Career: My six essential tips | Security Simplified
24
Mar
2023

Launching an InfoSec Career: My six essential tips | Security Simplified

Launching an InfoSec Career: My six essential tips | Security Simplified Source link

Bug Bounties With Bash - VirSecCon2020 Talk
24
Mar
2023

Bug Bounties With Bash – VirSecCon2020 Talk

Bug Bounties With Bash – VirSecCon2020 Talk Source link

[tl;dr sec] #174 - Mitigating SSRF in 2023, Isolation & Container Namespaces, Offensive AI Compilation
24
Mar
2023

[tl;dr sec] #174 – Mitigating SSRF in 2023, Isolation & Container Namespaces, Offensive AI Compilation

Hey there, I hope you’ve been doing well! Lift-ed Spirits Despite living within a few hour drive of Tahoe for…

Linus Tech Tips Got HACKED! :o
24
Mar
2023

Linus Tech Tips Got HACKED! :o

Linus Tech Tips Got HACKED! 😮 Source link

HackerOne
24
Mar
2023

HackerOne

Uber disclosed a bug submitted by zhero_: https://hackerone.com/reports/1790444 – Bounty: $650 Source link