Category: Mix

New vulnerability findings: Joomla, JBoss, Jenkins and others!
24
May
2023

The basics of Cross-site Scripting (XSS)

A lot can go wrong on the Internet and XSS is without a doubt one of the most common web…

10 Ways to Hack Your “New Normal” Workweek
24
May
2023

The European Commission’s First-Ever Bug Bounty Program

The European Commission has selected HackerOne as the platform for their first ever bug bounty program. This not only expands…

The basics of Local File Inclusions
24
May
2023

The basics of Local File Inclusions

Local File Inclusion is quite simply the act of including files that are stored on the web server you are…

What to Look For in a Penetration Testing Company
24
May
2023

Hacking the U.S. Air Force (again) from a New York City subway station

New York City during the holidays. Magical. Bringing together hackers from around the world to legally hack the U.S. Air…

An intelligent way to look for vulnerabilities
24
May
2023

Malicious Data Mining @ HyperIsland

Johan Edholm and I (Fredrik Nordberg Almroth) had a talk a while back at HyperIsland, Stockholm (the 18’th of October) for the DDS13 group….

Bug Bytes #201 – Path Traversal, Prompt Injection, and GitHub Actions
24
May
2023

Bug Bytes #201 – Path Traversal, Prompt Injection, and GitHub Actions

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by…

H1-415 Recap: Oath Pays Over $400,000 to Hackers in One Day
24
May
2023

Alex Rice and Zane Lackey Discuss Modern Security for Practitioners

Our co-founder and CTO, Alex Rice, was a recent guest on The Modern Security Series by Signal Sciences, along with…

How I hacked Facebook and received a $3,500 USD Bug Bounty
24
May
2023

How I hacked Facebook and received a $3,500 USD Bug Bounty

Find out how our Security Researcher Frans Rosén hacked Facebook and found a stored XSS for which he received a bug…

There is no room for racism or inequality here.
24
May
2023

Samy Kamkar’s Security@ San Francisco Keynote

If you were into social networks during the MySpace era, you might recall the Samy Worm of 2005. The worm…

New vulnerability findings: Joomla, JBoss, Jenkins and others!
24
May
2023

Server-side Javascript Injections and more!

Today’s updates fill the needs of many of you out there! You asked for it, and now it’s in the…

Juneteenth: HackerOne’s Day for Action
24
May
2023

Hacking The Planet – Hack The World 2017 Recap

After 1 month of our community’s best and brightest going head to head to be named Hack The World 2017…

An intelligent way to look for vulnerabilities
24
May
2023

Detectify Responsible Disclosure Program – Detectify Blog

As of today, researchers can report security issues in Detectify services to earn a spot on our Hall of Fame…