HackerOne
@HackerOne
11K
subscribers
644
photos
31
videos
79
files
2.74K
links
Community :
@Sec0x01
@Bug0x
Download Telegram
Join
HackerOne
11K subscribers
HackerOne
https://www.youtube.com/watch?v=Rci5xiyMv7k
HackerOne
HackerOne
https://www.hackingarticles.in/burp-suite-for-pentester-web-scanner-crawler/
Hacking Articles
Burp Suite for Pentester: Web Scanner & Crawler
Learn how to use Burp Suite's web scanner and crawler tools for identifying vulnerabilities and mapping web applications now.
HackerOne
https://www.youtube.com/watch?v=oe11Q-3Akuk
YouTube
Reflective C# Assembly loading && Reflective PE-Injection
In this stream I went through the process of C# source code modification, and reflective loading of C# Assemblies from Powershell. Afterwards, two public reflective PE-Loaders and the use-case with examples were shown. In the very end unhooking + ETW patching…
HackerOne
https://twitter.com/ESETresearch/status/1458438155149922312?s=20
Twitter
ESET research
#ESETresearch discovered a trojanized IDA Pro installer, distributed by the #Lazarus APT group. Attackers bundled the original IDA Pro 7.5 software developed by @HexRaysSA with two malicious components. @cherepanov74 1/5
HackerOne
https://github.com/0xCGonzalo/Golden-Guide-for-Pentesting
GitHub
GitHub - 0xCGonzalo/Golden-Guide-for-Pentesting: Golden Guide
Golden Guide. Contribute to 0xCGonzalo/Golden-Guide-for-Pentesting development by creating an account on GitHub.
HackerOne
https://youtu.be/Wlr1VQCo_5g
YouTube
django sql injection | The D is silent
CVE-2021-35042: Potential SQL injection via unsanitized QuerySet.order_by() input. Unsanitized user input passed to QuerySet.order_by() could bypass intended column reference validation in path marked for deprecation resulting in a potential SQL injection…
HackerOne
sample ransomware mail
HackerOne
https://hide01.ir
HideZeroOne
مرجع دانلود دوره های تست نفوذ و امنیت
HackerOne
HackerOne
Forwarded from
Security Analysis
CVE-2021-42321POC.py
7.7 KB
⭕️
PoC of MS Exchange RCE via mspaint.exe
@securation
HackerOne
https://certitude.consulting/blog/en/invisible-backdoor/
HackerOne
http://blog.howdays.kr/index.php/2021/11/26/virtualbox-6-1-18-0-day/
HackerOne
https://hackerone.com/reports/1363672
HackerOne
Shopify disclosed on HackerOne: Bypass a fix for report #708013
## Summary:
`customerAccessTokenCreate` mutation in the Storefront API does not correctly throttle login attempts. An issue in similar report https://hackerone.com/reports/708013 was already fixed,...
HackerOne
https://youtu.be/EwEABCBI3-g
YouTube
HackTheBox Cyber Santa CTF 2021 - Naughty or Nice - Web Challenge - Day5
Video walk-through for the Web Challenge called "Naughty or Nice" from Day 5 of the HTB "Cyber Santa is Coming to Town" Capture The Flag event that was going on from December 1st to December 5th 2021.
#hackthebox #CTF #SANTA #santa #cyber #web #challenges…
HackerOne
https://twitter.com/1rpwn/status/1469240466071859213
Twitter
Adel
sudo grep -r '${jndi:ldap://' /var/log sudo egrep -i -r '\$\{jndi:(ldap[s]?|rmi)://' /var/log #log4j #log_4jrce #RCE #apache
HackerOne
patched code
https://github.com/apache/logging-log4j2/pull/608/files/5f81dd218aab36bf1c6a7410c88c29594bb1a0e7#diff-271353c1076e53f6893261e4420de27d34588bfd782806b5c66a3465c43b7f51
GitHub
Restrict LDAP access via JNDI by rgoers · Pull Request #608 · apache/logging-log4j2
Restricts access to LDAP via JNDI.
HackerOne
https://twitter.com/80vul/status/1470272820571963392
Twitter
heige
[Bad news] Ransomware has landed on #log4j2 RCE
HackerOne
https://jfrog.com/blog/tensorflow-python-code-injection-more-eval-woes/
JFrog
TensorFlow Python Code Injection: More eval() Woes
Background JFrog security research team (formerly Vdoo) has recently disclosed a code injection issue in one of the utilities shipped with TensorFlow, a popular Machine Learning platform that’s widely used in the industry. The issue has been assigned to CVE…
HackerOne
HackerOne
https://github.com/icyguider/DumpNParse
GitHub
GitHub - icyguider/DumpNParse: A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0.
A Combination LSASS Dumper and LSASS Parser. All Credit goes to @slyd0g and @cube0x0. - icyguider/DumpNParse
TWeb.init({scrollToPost:'HackerOne/3238'});