Hacking Starbucks and Accessing Nearly 100 Million Customer Records
19
Mar
2023

Hacking Starbucks and Accessing Nearly 100 Million Customer Records

After a long day of trying and failing to find vulnerabilities on the Verizon Media bug bounty program I decided…

ropnop blog
19
Mar
2023

OWASP Chicago 2018 – Pentesting with Serverless Infrastructure

Slides Supplemental Serverless Toolkit available here: https://github.com/ropnop/serverless_toolkit Source link

The Mystery of postMessage – Ron Chan
19
Mar
2023

The Mystery of postMessage – Ron Chan

From time to time we see postMessage bug in H1 hacktivity, some write ups mentioning the word postMessage, but do…

I Got Investigated by the Secret Service. Here's How to Not Be Me
19
Mar
2023

I Got Investigated by the Secret Service. Here’s How to Not Be Me

Unfortunately, my thought process wasn’t that complex when I suddenly had to talk to a federal agent on my phone…

Microsoft Outlook Vulnerability Actively Exploited
19
Mar
2023

Microsoft Outlook Vulnerability Actively Exploited

Recently, Microsoft released a series of patches to address around 80 security vulnerabilities, including two zero-day exploits. One of the…

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE...
19
Mar
2023

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE…

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE… Source link

19
Mar
2023

Week in review: Kali Linux gets Purple, Microsoft zero-days get patched

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Samsung, Vivo, Google phones open…

Enumerating hard to guess AD username format
19
Mar
2023

Enumerating hard to guess AD username format

I quite enjoy external Pentest, especially when the scope is large. There has been some really interesting stuff I have…

Tips and Scripts from a Hacker Dad · rez0
19
Mar
2023

Tips and Scripts from a Hacker Dad · rez0

As a hacker and bug bounty hunter, I spend a lot of my time optimizing and improving. So, as a…

Cookie Tossing
19
Mar
2023

Cookie Tossing

Cookie Tossing Source link

GISEC Global 2023
19
Mar
2023

Mohamed Hamad Al-Kuwaiti Recognized For Cybersecurity Contributions

H.E. Dr. Mohamed Hamad Al-Kuwaiti, Head of the UAE Cybersecurity Council, was recognized and celebrated by hundreds of cyber leaders…

Smuggling an (Un)exploitable XSS – RCE Security
19
Mar
2023

Smuggling an (Un)exploitable XSS – RCE Security

This is the story about how I’ve chained a seemingly uninteresting request smuggling vulnerability with an even more uninteresting header-based…