PwnScriptum (PHP Mailer Remote Code Execution) Zafiyeti
https://www.netsparker.com.tr/blog/web-guvenligi/Meraklisi-icin-PwnScriptum-Zafiyeti-PHP-Mailer-Remote-Code-Execution/
https://www.netsparker.com.tr/blog/web-guvenligi/Meraklisi-icin-PwnScriptum-Zafiyeti-PHP-Mailer-Remote-Code-Execution/
Netsparker - Web Uygulaması Güvenlik Tarayıcısı
Meraklısı İçin PwnScriptum (PHP Mailer Remote Code Execution) Zafiyeti
PHP Mailer'de tespit edilen PwnScriptum'dan hareketle, diğer kütüphanelerde de benzer yollarla açığa çıkan zafiyetin teknik ayrıntıları.
[render.bitstrips.com] Stored XSS via an incorrect avatar property value
https://hackerone.com/reports/159878
https://hackerone.com/reports/159878
HackerOne
Snapchat disclosed on HackerOne: [render.bitstrips.com] Stored XSS...
While modifying an avatar, an attacker has the opportunity to submit XSS payloads as its property values. The resulting png file will return a 500 error with the payload in the response body. The...
Forwarded from دیالوگ های ماندگار💂
تف به این شانس ... چرا هرکاری که ما توش خبره ایم غیرقانونیه ؟!
📽 Butch Cassidy and the Sundance Kid (1969)
🎭 @dialoghmandegar
📽 Butch Cassidy and the Sundance Kid (1969)
🎭 @dialoghmandegar
https://hackerone.com/reports/188743
xxe in DOD 😐
xxe in DOD 😐
HackerOne
U.S. Dept Of Defense disclosed on HackerOne: XXE on DoD web server
A Department of Defense webserver was vulnerable to an XML External Entity (XXE) processing vulnerability. dawgyg was able to exploit this vulnerability by crafting an XML request that revealed...
Critical : Malware and XSS file can be uploaded and executed on udemy
https://hackerone.com/reports/172694
https://hackerone.com/reports/172694
HackerOne
Udemy disclosed on HackerOne: Critical : Malware and XSS file can...
The investigator found that he can upload any file type to our upload bucket. That is intended behavior - file content is enforced before moving it out of our upload bucket.
Attacking UEFI Runtime Services and Linux
http://blog.frizk.net/2017/01/attacking-uefi-and-linux.html
http://blog.frizk.net/2017/01/attacking-uefi-and-linux.html
blog.frizk.net
Attacking UEFI Runtime Services and Linux
Attackers with physical access are able to attack the firmware on many fully patched computers with DMA - Direct Memory Access. Once code ex...
Oops!
FaceBook Remote Code Excution
http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html
FaceBook Remote Code Excution
http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html