Please open Telegram to view this post
VIEW IN TELEGRAM
Sayaan Alam
Exploiting Freemarker SSTI for Remote Code Execution
Hi Readers!
I hope you all are doing well,
In this post, I want to discuss a specific type of vulnerability I've encountered: Server-Side Template Injection (SSTI) in Freemarker that can lead to Remote Code Execution (RCE). This vulnerability is part...
I hope you all are doing well,
In this post, I want to discuss a specific type of vulnerability I've encountered: Server-Side Template Injection (SSTI) in Freemarker that can lead to Remote Code Execution (RCE). This vulnerability is part...
❤3
Please open Telegram to view this post
VIEW IN TELEGRAM
Labs Detectify
Account hijacking using "dirty dancing" in sign-in OAuth-flows
Combining response-type switching, invalid state and redirect-uri quirks using OAuth, with third-party javanoscript-inclusions has multiple vulnerable scenarios where authorization codes or tokens could leak to an attacker. This could be used in attacks for…
❤4🔥2 2 1
🔥3
Forwarded from Brut Security
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3👍3
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3
Please open Telegram to view this post
VIEW IN TELEGRAM
Writeups
Android web attack surface
The following is a writeup for some Android specific chromium behaviors.
❤3
👍2🔥2
Forwarded from Android Security & Malware
Malimite: iOS decompiler designed to analyze and decode IPA files
Built on top of Ghidra to offer direct support for Swift, Objective-C, and iOS resources
https://github.com/LaurieWired/Malimite
Built on top of Ghidra to offer direct support for Swift, Objective-C, and iOS resources
https://github.com/LaurieWired/Malimite
GitHub
GitHub - LaurieWired/Malimite: iOS and macOS Decompiler
iOS and macOS Decompiler. Contribute to LaurieWired/Malimite development by creating an account on GitHub.
❤3