Q: How to write a BUG BOUNTY report that actually gets paid?
19
Mar
2023

Q: How to write a BUG BOUNTY report that actually gets paid?

Q: How to write a BUG BOUNTY report that actually gets paid? Source link

Custom Taskpane Remote
19
Mar
2023

Embedding Payloads and Bypassing Controls in Microsoft InfoPath

While browsing a SharePoint instance recently, I came across an interesting URL in the form https:///_layouts/FormServer.aspx?XsnLocation=https:///resource/Forms/template.xsn. The page itself displayed…

Botnet
19
Mar
2023

New ‘HinataBot’ botnet could launch massive 3.3 Tbps DDoS attacks

A new malware botnet was discovered targeting Realtek SDK, Huawei routers, and Hadoop YARN servers to recruit devices into DDoS…

Challenge
19
Mar
2023

Full Stack Web Attack 2021 :: Zero Day Give Away

This year I released a challenge for the Full Stack Web Attack class: Whilst several people had solved the challenge,…

Discovering a zero day and getting code execution on Mozilla's AWS Network – Assetnote
19
Mar
2023

Discovering a zero day and getting code execution on Mozilla’s AWS Network – Assetnote

When Assetnote Continuous Security (CS) monitors your attack surface, one of the things it looks for are instances of WebPageTest….

new relic dashboards
19
Mar
2023

Get as image function pulls any Insights/NRQL data from any New Relic account (IDOR)

This writeup walks you through the full process as to how I found a pretty bad Insecure Direct Object Reference…

Hacking Starbucks and Accessing Nearly 100 Million Customer Records
19
Mar
2023

Hacking Starbucks and Accessing Nearly 100 Million Customer Records

After a long day of trying and failing to find vulnerabilities on the Verizon Media bug bounty program I decided…

ropnop blog
19
Mar
2023

OWASP Chicago 2018 – Pentesting with Serverless Infrastructure

Slides Supplemental Serverless Toolkit available here: https://github.com/ropnop/serverless_toolkit Source link

The Mystery of postMessage – Ron Chan
19
Mar
2023

The Mystery of postMessage – Ron Chan

From time to time we see postMessage bug in H1 hacktivity, some write ups mentioning the word postMessage, but do…

I Got Investigated by the Secret Service. Here's How to Not Be Me
19
Mar
2023

I Got Investigated by the Secret Service. Here’s How to Not Be Me

Unfortunately, my thought process wasn’t that complex when I suddenly had to talk to a federal agent on my phone…

Microsoft Outlook Vulnerability Actively Exploited
19
Mar
2023

Microsoft Outlook Vulnerability Actively Exploited

Recently, Microsoft released a series of patches to address around 80 security vulnerabilities, including two zero-day exploits. One of the…

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE...
19
Mar
2023

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE…

INTERVIEW WITH @_BASE_64 : 19 Y/o | TOP 150 WORLDWIDE on H1 | METHODOLOGY, MINDSET & MORE… Source link