HackerOne
@HackerOne
11K
subscribers
644
photos
31
videos
79
files
2.74K
links
Community :
@Sec0x01
@Bug0x
Download Telegram
Join
HackerOne
11K subscribers
HackerOne
https://hackerone.com/reports/288704
HackerOne
Phabricator disclosed on HackerOne: Command injection on...
Hi phabricator,
I found an evil branch name of hg a repo can lead to arbitrary command injection on phabricator instance.
Here is the reproduction steps:
1. Monitor a remote mercurial repo with...
HackerOne
HackerOne
https://hackerone.com/reports/117073
HackerOne
Informatica disclosed on HackerOne: [informatica.com] Blind SQL...
Hi guys!
JSON POST parameter "docId" is vulnerable to Blind SQL Injection attack
PoC (Raw query)
POST /_vti_bin/RatingsCalculator/RatingsCalculator.asmx/CalculateRatings HTTP/1.1
User-Agent:...
HackerOne
https://github.com/We5ter/Scanners-Box
GitHub
GitHub - We5ter/Scanners-Box: A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑 - We5ter/Scanners-Box
HackerOne
https://medium.com/bread-and-circuses/how-i-got-paid-0-from-the-uber-security-bug-bounty-aa9646aa103f
HackerOne
Forwarded from
burpsuite (not official)
burpsuite_pro_v1.7.30.zip
26 MB
pass: 311138
Happy Hacking in new Year!
👍
1
HackerOne
This media is not supported in your browser
VIEW IN TELEGRAM
HackerOne
https://hackerone.com/reports/293359
HackerOne
Uber disclosed on HackerOne: The Uber Promo Customer Endpoint Does...
## Summary
The https://cn-sjc1.uber.com/rt/users/apply-clients-promotions customer endpoint used to apply Uber promotions does not implement multifactor authentication, IP address blacklisting for...
HackerOne
https://hackerone.com/reports/293359
HackerOne
Uber disclosed on HackerOne: The Uber Promo Customer Endpoint Does...
## Summary
The https://cn-sjc1.uber.com/rt/users/apply-clients-promotions customer endpoint used to apply Uber promotions does not implement multifactor authentication, IP address blacklisting for...
HackerOne
http://www.sxcurity.pro/2017/12/17/hackertarget/
www.provensecurity.co
Proven Security
Security consulting and pentesting by proven security experts.
HackerOne
https://www.kitploit.com/2017/12/username-anarchy-username-tools-for.html?utm_source=dlvr.it&utm_medium=twitter
KitPloit - PenTest Tools for your Security Arsenal
☣
Username Anarchy - Username Tools For Penetration Testing
Leading source of Security Tools, Hacking Tools, CyberSecurity and Network Security
☣
HackerOne
HackerOne
https://www.kaspersky.com/blog/cybersecurity-crossword/19751/
Kaspersky
Crossword: Cybersecurity terms
Test your knowledge of cybersecurity terms and concepts with our crossword puzzle.
HackerOne
https://blog.xpnsec.com/anti-debug-openprocess
XPN InfoSec Blog
@_xpn_ - Windows Anti-Debug techniques - OpenProcess filtering
This week I took a break from SYSTEM chasing to review some anti-debugging techniques. With quite a few Bug Bounty programs available relying on client-side applications, I thought I'd share one of the techniques used by numerous security products (and apparently…
HackerOne
http://gxamjbnu7uknahng.onion/wiki/index.php/Main_Page
HackerOne
HackerOne
HackerOne
https://www.youtube.com/watch?v=fA6W9_zLCeA
YouTube
34C3 - 1-day exploit development for Cisco IOS
https://media.ccc.de/v/34c3-8936-1-day_exploit_development_for_cisco_ios
Year 2017 was rich in vulnerabilities discovered for Cisco networking devices. At least 3 vulnerabilities leading to a remote code execution were disclosed. This talk will give an…
HackerOne
security-testing-kali-nethunter.rar
12.1 MB
HackerOne
❤
1
HackerOne
http://witcoat.blogspot.com/2017/12/stealing-10000-yahoo-cookies.html
Blogspot
Stealing $10,000 Yahoo Cookies!
Hi, This is my second blog post. I recently started to noscript python, So I decided to write some recon noscript to filter out domains to at...
TWeb.init({scrollToPost:'HackerOne/1472'});