Category: Mix

vROps
12
Mar
2023

Pre-Authenticated RCE in VMWare vRealize Operations Manager

On May 27th, I reported a handful of security vulnerabilities to VMWare impacting their vRealize Operations Management Suite (vROps) appliance….

Finding Hidden Files and Folders on IIS using BigQuery – Assetnote
12
Mar
2023

Finding Hidden Files and Folders on IIS using BigQuery – Assetnote

  Motivations I recently made a video on how to find hidden files and folders on IIS through the use…

Don’t Reply: A Clever Phishing Method In Apple's Mail App
12
Mar
2023

Don’t Reply: A Clever Phishing Method In Apple’s Mail App

About four or five years ago, friend and fellow bug bounty hunter Sam Curry asked if I had “ever thought…

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
12
Mar
2023

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

Overview On August 24th, 2022, we reported a vulnerability to Netlify affecting their Next.js “netlify-ipx” repository which would allow an…

ropnop blog
12
Mar
2023

ChiBrrCon 2020: Don’t Cross Me! Same Origin Policy and all the “cross” vulns

ChiBrrCon 2020: Don’t Cross Me! Same Origin Policy and all the “cross” vulns Source link

[Google VRP] SSRF in Google Cloud Platform StackDriver – Ron Chan
12
Mar
2023

[Google VRP] SSRF in Google Cloud Platform StackDriver – Ron Chan

During the process of testing GAE after reading this awesome blog post, I found a debug application in Google Cloud…

FROM 0 to $$$$ - MY BIGGEST BUG BOUNTY LEARNINGS!
12
Mar
2023

FROM 0 to $$$$ – MY BIGGEST BUG BOUNTY LEARNINGS!

FROM 0 to $$$$ – MY BIGGEST BUG BOUNTY LEARNINGS! Source link

Bountycon2020 Presentation | Richard’s Infosec blog
12
Mar
2023

Bountycon2020 Presentation | Richard’s Infosec blog

I was recently invited to present at BountyCon 2020. This was supposed to early March in Singapore where flights and…

How to Spend Time Well, A Framework · rez0
12
Mar
2023

How to Spend Time Well, A Framework · rez0

For a healthy person in a first world country, the number of things we could do is near infinite. And…

Include This In Your Hacking Workflow by Continuous Monitoring with AuthoGraphQL (How-to guide)
12
Mar
2023

Include This In Your Hacking Workflow by Continuous Monitoring with AuthoGraphQL (How-to guide)

Include This In Your Hacking Workflow by Continuous Monitoring with AuthoGraphQL (How-to guide) Source link

Samesite by Default and What It Means for Bug Bounty Hunters
12
Mar
2023

Samesite by Default and What It Means for Bug Bounty Hunters

31 January 2020 You have probably heard of the SameSite attribute addition to HTTP cookies since Chrome 51 (and a…

Exploiting a Blind SQL Injection via XSS – RCE Security
11
Mar
2023

Exploiting a Blind SQL Injection via XSS – RCE Security

Introduction You probably have read about my recent swamp of CVEs affecting a WordPress plugin called Transposh Translation Filter, which…