Category: Mix

CSRF protection on OIDC login is broken
08
Apr
2023

CSRF protection on OIDC login is broken

Nextcloud disclosed a bug submitted by mikaelgundersen: https://hackerone.com/reports/1878381 Source link

Top 3 Most Dangerous Lines of Code
07
Apr
2023

Top 3 Most Dangerous Lines of Code

Top 3 Most Dangerous Lines of Code Source link

Firefox privacy and security hardening guide (2022 revised edition)
07
Apr
2023

Firefox privacy and security hardening guide (2022 revised edition)

Firefox privacy and security hardening guide (2022 revised edition) Source link

Easily leaking passenger information on an Airline | by Sean (zseano)
07
Apr
2023

Easily leaking passenger information on an Airline | by Sean (zseano)

This post is going to outline how I simply applied my methodology and managed to find multiple vulnerabilities leaking airline…

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman
07
Apr
2023

Reflected XSS at Philips.com. A full write-up; reflected XSS was… | by Jonathan Bouman

Proof of concept Are you aware of any (private) bug bounty programs? I would love to get an invite. Please…

BOUNTY THURSDAYS - LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)
07
Apr
2023

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions)

BOUNTY THURSDAYS – LIVE #1 (SVG-XML/Redirects/OOB servers and Community Questions) Source link

Facebook Gameroom
07
Apr
2023

Applying Offensive Reverse Engineering to Facebook Gameroom

Late last year, I was invited to Facebook’s Bountycon event, which is an invitation-only application security conference with a live-hacking…

Remotely Managing Hyper-V in a Workgroup Environment
07
Apr
2023

Remotely Managing Hyper-V in a Workgroup Environment

A few weekends ago, I decided (because apparently I’m a masochist) that I was tired of the free version of…

How I could Steal Your Google Bug Hunter Account with Two Clicks in IE – Ron Chan
07
Apr
2023

How I could Steal Your Google Bug Hunter Account with Two Clicks in IE – Ron Chan

This post is another evidence to show how difficult to parse a URL correctly. IE has URL parsing problem, this…

No BS Guide - Better Subdomain Enumeration
07
Apr
2023

No BS Guide – Better Subdomain Enumeration

No BS Guide – Better Subdomain Enumeration Source link

Hacker cats · rez0
07
Apr
2023

Hacker cats · rez0

A collection of AI-generated Hacker Cats If you want to see an image in full resolution, you can right click…

What's the shortest domain? | Unicode Hacking & Tricks
07
Apr
2023

What’s the shortest domain? | Unicode Hacking & Tricks

What’s the shortest domain? | Unicode Hacking & Tricks Source link