Windows 11
12
Mar
2023

Microsoft finally fixes Windows 11 slow file copy issues over SMB

Microsoft has finally addressed a known issue causing significant performance hits when copying large files over SMB after installing the…

How to turn bugs into a "passive" income stream! ft Detectify's Almroot
12
Mar
2023

How to turn bugs into a “passive” income stream! ft Detectify’s Almroot

How to turn bugs into a “passive” income stream! ft Detectify’s Almroot Source link

Staples
12
Mar
2023

Staples-owned Essendant facing multi-day “outage,” orders frozen

Essendant, a wholesale distributor of stationary and office supplies, is experiencing a multi-day systems “outage” preventing customers and suppliers from…

Zoom Whiteboard
12
Mar
2023

I Hope This Sticks: Analyzing ClipboardEvent Listeners for Stored XSS

When is copy-paste payloads not self-XSS? When it’s stored XSS. Recently, I reviewed Zoom’s code to uncover an interesting attack…

vROps
12
Mar
2023

Pre-Authenticated RCE in VMWare vRealize Operations Manager

On May 27th, I reported a handful of security vulnerabilities to VMWare impacting their vRealize Operations Management Suite (vROps) appliance….

Finding Hidden Files and Folders on IIS using BigQuery – Assetnote
12
Mar
2023

Finding Hidden Files and Folders on IIS using BigQuery – Assetnote

  Motivations I recently made a video on how to find hidden files and folders on IIS through the use…

Don’t Reply: A Clever Phishing Method In Apple's Mail App
12
Mar
2023

Don’t Reply: A Clever Phishing Method In Apple’s Mail App

About four or five years ago, friend and fellow bug bounty hunter Sam Curry asked if I had “ever thought…

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library
12
Mar
2023

Exploiting Web3’s Hidden Attack Surface: Universal XSS on Netlify’s Next.js Library

Overview On August 24th, 2022, we reported a vulnerability to Netlify affecting their Next.js “netlify-ipx” repository which would allow an…

ropnop blog
12
Mar
2023

ChiBrrCon 2020: Don’t Cross Me! Same Origin Policy and all the “cross” vulns

ChiBrrCon 2020: Don’t Cross Me! Same Origin Policy and all the “cross” vulns Source link

[Google VRP] SSRF in Google Cloud Platform StackDriver – Ron Chan
12
Mar
2023

[Google VRP] SSRF in Google Cloud Platform StackDriver – Ron Chan

During the process of testing GAE after reading this awesome blog post, I found a debug application in Google Cloud…

Week in review: Public MS Word RCE PoC, API exploitation, Patch Tuesday forecast
12
Mar
2023

Week in review: Public MS Word RCE PoC, API exploitation, Patch Tuesday forecast

Microsoft to boost protection against malicious OneNote documentsMicrosoft has announced that, starting in April 2023, they will be adding enhanced…

FROM 0 to $$$$ - MY BIGGEST BUG BOUNTY LEARNINGS!
12
Mar
2023

FROM 0 to $$$$ – MY BIGGEST BUG BOUNTY LEARNINGS!

FROM 0 to $$$$ – MY BIGGEST BUG BOUNTY LEARNINGS! Source link