Introducing Varanid.io! Varanid can monitor DNS records, SSL certificates, and any file changes, with support for beautiful email, Slack, and custom webhook notifications. Perfect for a professional and reliable monitoring setup.
Via: https://twitter.com/varanidio/status/1176506299732959235
Via: https://twitter.com/varanidio/status/1176506299732959235
YESWEHACK PROPHILE ON AK1T4
https://blog.yeswehack.com/2019/09/24/yeswehack-prophile-on-ak1t4/
https://blog.yeswehack.com/2019/09/24/yeswehack-prophile-on-ak1t4/
Global Bug Bounty Platform
YESWEHACK PROPHILE ON Ak1t4 - Global Bug Bounty Platform
We are moving towards a virtual society where the mind will be more closer to the illusion than the plain reality ( it's already happening )
vBulletin 5.x 0day pre-auth RCE exploit
https://seclists.org/fulldisclosure/2019/Sep/31
https://seclists.org/fulldisclosure/2019/Sep/31
seclists.org
Full Disclosure: vBulletin 5.x 0day pre-auth RCE exploit
XSS and Open Redirect on MoPub Login
https://hackerone.com/reports/683298
https://hackerone.com/reports/683298
HackerOne
X / xAI disclosed on HackerOne: XSS and Open Redirect on MoPub Login
Very simple open redirect made more impactful by the lack of filtering javanoscript URIs. Thanks again to the Twitter team for a quick response/bounty!
The return of the <
https://hackerone.com/reports/639684
https://hackerone.com/reports/639684
HackerOne
Rockstar Games disclosed on HackerOne: The return of the <
In this report, the researcher was able to demonstrate a Stored XSS vulnerability in our Message system on the Social Club website. By taking advantage of the fact that '<' characters are...
Privilege escalation in workers container
https://hackerone.com/reports/692603
https://hackerone.com/reports/692603
HackerOne
Semmle disclosed on HackerOne: Privilege escalation in workers...
## Summary about the bugs:
In the prepare step, semmle allows user to install new package.
By upload a malicious package along with source code and force server to build this package, attacker...
In the prepare step, semmle allows user to install new package.
By upload a malicious package along with source code and force server to build this package, attacker...
CSRF Testing Mind Map
https://twitter.com/s0md3v/status/1176521784826331136?
https://twitter.com/s0md3v/status/1176521784826331136?
Arbitrary file creation with semi-controlled content (leads to DoS, EoP and others) at Steam Windows Client
https://hackerone.com/reports/682774
https://hackerone.com/reports/682774
HackerOne
Valve disclosed on HackerOne: Arbitrary file creation with...
The vulnerability allows to create arbitrary file with some crafted text (or append to existing file). Tested on actual version 5.31.28.21 (SteamService.exe filevesion info). At start of the report...
One XSS cheatsheet to rule them all
https://portswigger.net/research/one-xss-cheatsheet-to-rule-them-all
https://portswigger.net/research/one-xss-cheatsheet-to-rule-them-all
PortSwigger Research
One XSS cheatsheet to rule them all
PortSwigger are proud to launch our brand new XSS cheatsheet. Our objective was to build the most comprehensive bank of information on bypassing HTML filters and WAFs to achieve XSS, and to present th
Normalized Stored XSS (\xef\xbc\x9c => \x3c)
https://www.hahwul.com/2019/09/normalized-stored-xss.html
https://www.hahwul.com/2019/09/normalized-stored-xss.html
Ability to perform actions (Tweet, Retweet, DM) and other actions, unauthenticated, on any account with SMS enabled.
https://hackerone.com/reports/470749
https://hackerone.com/reports/470749
HackerOne
Twitter disclosed on HackerOne: Ability to perform actions (Tweet,...
**Summary:** By knowing the mobile phone number associated with a Twitter account, or by using random mobile phone numbers! It is possible to perform the following actions against a target without...
Сookie-based XSS exploitation | $2300 Bug Bounty story
https://medium.com/@iSecMax/%D1%81ookie-based-xss-exploitation-2300-bug-bounty-story-9bc532ffa564
https://medium.com/@iSecMax/%D1%81ookie-based-xss-exploitation-2300-bug-bounty-story-9bc532ffa564
Medium
Сookie-based XSS exploitation | $2300 Bug Bounty story
For quite a long time I have been hunting for vulnerabilities on the HackerOne platform, allocating a certain amount of time outside the…
My baby steps towards Bug Bounty Hunting — an arduous yet exciting journey
https://medium.com/@sankethsharath/my-baby-steps-towards-bug-bounty-hunting-an-exciting-yet-arduous-journey-f92ca12eb039
https://medium.com/@sankethsharath/my-baby-steps-towards-bug-bounty-hunting-an-exciting-yet-arduous-journey-f92ca12eb039
Medium
My baby steps towards Bug Bounty Hunting — an arduous yet exciting journey
It’s fascinating, how life has its twisted plots. I am an Oral Pathologist (a specialty in Dentistry) by education, an Entrepreneur by…
[1/n] Practical walkthrough on how I found an XSS injection and used @PortSwigger @garethheyes XSS cheatsheet to bypass a WAF on a @Hacker0x01 program recently:
Via: https://twitter.com/spaceraccoonsec/status/1177877957844459520
Via: https://twitter.com/spaceraccoonsec/status/1177877957844459520
HackBar V2
[No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
https://addons.mozilla.org/en-US/firefox/addon/hackbar-free/
[No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
https://addons.mozilla.org/en-US/firefox/addon/hackbar-free/
addons.mozilla.org
HackBar V2 – Get this Extension for 🦊 Firefox (en-US)
Download HackBar V2 for Firefox. [No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
You can ask request here: https://github.com/Hack-Free/HackBar
You can ask request here: https://github.com/Hack-Free/HackBar
If you find powerful OXML XXE tool? it's "DOCEM"
https://www.hahwul.com/2019/09/oxml-xxe-payload-inject-tool-docem.html
https://www.hahwul.com/2019/09/oxml-xxe-payload-inject-tool-docem.html