he Source Code Sniffer is a poor man’s static code analysis tool (SCA) that leverages regular expressions. Designed to highlight high risk functions (Injection, LFI/RFI, file uploads etc) across multiple languages (ASP, Java, CSharp, PHP, Perl, Python, JavaScript, HTML etc) in a highly configurable manner.
https://github.com/frizb/SourceCodeSniffer
https://github.com/frizb/SourceCodeSniffer
Gaining Filesystem Access via Blind OOB XXE
https://hawkinsecurity.com/2018/03/24/gaining-filesystem-access-via-blind-oob-xxe/
https://hawkinsecurity.com/2018/03/24/gaining-filesystem-access-via-blind-oob-xxe/
Tip Anti-CSRF token.
When faced with CSRF tokens, sometimes deleting the token parameter, sending an empty token or simply reusing your own token is sometimes more than enough to bypass some solutions of anti CSRF tokens
Via: https://twitter.com/alyssa_herrera_/status/977619512785649664?s=21
When faced with CSRF tokens, sometimes deleting the token parameter, sending an empty token or simply reusing your own token is sometimes more than enough to bypass some solutions of anti CSRF tokens
Via: https://twitter.com/alyssa_herrera_/status/977619512785649664?s=21
Twitter
When faced with CSRF tokens, sometimes deleting the token parameter, sending an empty token or simply reusing your own token is sometimes more than enough to bypass some solutions of anti CSRF tokens
h1-202 leaderboard photo discloses local wifi password
https://hackerone.com/reports/329798
https://hackerone.com/reports/329798
HackerOne
HackerOne disclosed on HackerOne: h1-202 leaderboard photo...
One of our photographers accidentally took a photograph that exposed the WiFi password of the H1-202 event, which we consider bad OPSEC. This photo was published on our Facebook page and the...
A journey in the insecurity of JSON Web Tokens : https://www.slideshare.net/mobile/snyff/jwt-insecurity
SlideShare
Jwt == insecurity?
Jwt == insecurity? - Download as a PDF or view online for free
2018-03-26 | Facebook’s Android app harvesting call logs, AutoFuzz patch rewards by Google, and The newcomers guide to threat actor naming https://www.hackerone.com/zerodaily/2018-03-26
Hackerone
2018-03-26 | Facebook’s Android app harvesting call logs, AutoFuzz patch rewards by Google, and The newcomers guide to threat actor…
Monday, March 26 TOP STORY
Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal)
https://medium.com/@logicbomb_1/bugbounty-rewarded-by-securing-vulnerabilities-in-bookmyshow-indias-largest-online-movie-bb81dba9b82
https://medium.com/@logicbomb_1/bugbounty-rewarded-by-securing-vulnerabilities-in-bookmyshow-indias-largest-online-movie-bb81dba9b82
Medium
#BugBounty — Rewarded by securing vulnerabilities in Bookmyshow (India’s largest online movie & event booking portal)
Hi Guys,
Reverb.com went public on Hacker0x01 today: https://hackerone.com/reverb
HackerOne
Reverb.com - Bug Bounty Program | HackerOne
The Reverb.com Bug Bounty Program enlists the help of the hacker community at HackerOne to make Reverb.com more secure. HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally…
Misconfiguration of Demographics Privacy in a Page
https://medium.com/@markchristiandeduyo/misconfiguration-of-demographics-privacy-in-a-page-682feb1179f2
https://medium.com/@markchristiandeduyo/misconfiguration-of-demographics-privacy-in-a-page-682feb1179f2
Medium
Misconfiguration of Demographics Privacy in a Page
Denoscription: Demographics is Limit Visibility of This Post, Choose who can see your post on Facebook based on their demographic. For…
From hacked client to 0day discovery
https://security.infoteam.ch/en/blog/posts/from-hacked-client-to-0day-discovery.html
https://security.infoteam.ch/en/blog/posts/from-hacked-client-to-0day-discovery.html
Infoteam Digital
Infoteam Digital | The Digital Partner For SMEs
Infoteam Digital supports companies in the digitalisation of their activities, in the daily management of their IT and in the training of their employees.
2018-03-27 | Aadhaar data leak, Facebook Container by Firefox, and XSS auditor reporting to report URI
https://www.hackerone.com/zerodaily/2018-03-27
https://www.hackerone.com/zerodaily/2018-03-27
Hackerone
2018-03-27 | Aadhaar data leak, Facebook Container by Firefox, and XSS auditor reporting to report URI | HackerOne
Tuesday, March 27 TOP STORY
Stored XSS (client-side, using cookie poisoning) on the pornhubpremium.com https://hackerone.com/reports/311948
[Bypass WAF] Php webshell without numbers and letters
https://securityonline.info/bypass-waf-php-webshell-without-numbers-letters/
https://securityonline.info/bypass-waf-php-webshell-without-numbers-letters/
Penetration Testing
[Bypass WAF] Php webshell without numbers and letters
php webshell, bypass waf php webshell, upload php webshell
2018-03-28 | City of Atlanta returns to the digital age, PowerPoint exploits are so choice, and That cryptomining side hustle
https://www.hackerone.com/zerodaily/2018-03-28
https://www.hackerone.com/zerodaily/2018-03-28
Hackerone
2018-03-28 | City of Atlanta returns to the digital age, PowerPoint exploits are so choice, and That cryptomining side hustle |…
Wednesday, March 28 TOP STORY The City of Atlanta flickers back to the digital age, still recovering from SamSam ransomware attack. HACKTIVITY
How to Hire a Rockstar Security Researcher For Your Company
https://blog.appknox.com/hire-security-researcher/
https://blog.appknox.com/hire-security-researcher/
Appknox
How to Hire a Rockstar Security Researcher For Your Company
Cybercrime is the greatest threat to every company in the world and the key to winning against cybersecurity threats is to incorporate security proactively
Upcoming Facebook Platform Changes
Reward people who find vulnerabilities: Facebook’s bug bounty program will expand so that people can also report to us if they find misuses of data by app developers. We are beginning work on this and will have more details as we finalize the program updates in the coming weeks.
https://developers.facebook.com/blog/post/2018/03/26/facebook-platform-changes/
Reward people who find vulnerabilities: Facebook’s bug bounty program will expand so that people can also report to us if they find misuses of data by app developers. We are beginning work on this and will have more details as we finalize the program updates in the coming weeks.
https://developers.facebook.com/blog/post/2018/03/26/facebook-platform-changes/
Extra program metrics disclosed via /PROGRAM_NAME json response
https://hackerone.com/reports/327088
https://hackerone.com/reports/327088
HackerOne
HackerOne disclosed on HackerOne: Extra program metrics disclosed...
**Summary:**
The response to www.hackerone.com/PROGRAM.json includes `sla_missed_count` `sla_failed_count` and `researcher_count`.
**Denoscription:**
Viewing the response from a program's json...
The response to www.hackerone.com/PROGRAM.json includes `sla_missed_count` `sla_failed_count` and `researcher_count`.
**Denoscription:**
Viewing the response from a program's json...
Bypass XSS Protection (Event Handler filtering) with string+slash
http://www.hahwul.com/2018/03/bypass-xss-protection-event-handler.html
http://www.hahwul.com/2018/03/bypass-xss-protection-event-handler.html