HackerOne – Telegram
HackerOne
11K subscribers
644 photos
31 videos
79 files
2.74K links
Community : @Sec0x01
@Bug0x
Download Telegram
Forwarded from CTF Community | Hints
Heavy-duty and Advanced Cross Site Scripting Scanner

https://github.com/haroonawanofficial/XSS-Finder
#web #xss #tool
@ctfplay
Abusing ImageMagick to obtain RCE

Remote Code Execution because of an image source? Is it Possible? Yes! Definitely. Here in this blog post, a Strynx team member found a variation of Remote Code Execution AKA RCE through ImageMagick which earned him a generous bounty of $5000. Amazingly, some tweaks inside the image source exfiltrated the data over DNS (also called side-channel attacks). Let’s see how was it done after a short introduction to ImageMagick.

https://strynx.org/imagemagick-rce/
https://siguza.github.io/PAN/

ARM CPU hardware bug
US warns of Iranian cyber threat

https://ift.tt/37LGRsP
new version of Boneh-Shoup's magnificent book is out!

https://crypto.stanford.edu/~dabo/cryptobook/BonehShoup_0_5.pdf