Forwarded from Android Security & Malware
How to setup Ninjutsu Android Penetration Testing Environment
https://ninjutsu-blog.github.io/2021/06/27/How-to-setup-Ninjutsu-Android-Penetration-Testing-Environment/
https://ninjutsu-blog.github.io/2021/06/27/How-to-setup-Ninjutsu-Android-Penetration-Testing-Environment/
Ninjutsu Project
How to setup Ninjutsu Android Penetration Testing Environment
Ninjutsu Android Penetration Testing EnvironmentThis is a portable android Penetration testing environment that includes specific tools to help you to conduct android applications. List of Tools insta
How I was able to Takeover Accounts on Foxit.com
https://gonzx.medium.com/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f
https://gonzx.medium.com/how-i-was-able-to-takeover-any-account-on-foxit-com-7a08efa0144f
Medium
How I was able to Takeover Accounts on Foxit.com
Hello to all Security Researchers and Bug Hunters who is reading this blog, Im Jefferson Gonzales also new in bug hunting, so without…
Introducing DOM Invader: DOM XSS just got a whole lot easier to find https://portswigger.net/blog/introducing-dom-invader
PortSwigger Blog
Introducing DOM Invader: DOM XSS just got a whole lot easier to find
Of the three main types of XSS, DOM-based XSS is by far the most difficult to find and exploit. But we come bearing good news! PortSwigger just released a new tool for Burp Suite Professional and Burp
Finding DOM Polyglot XSS in PayPal the Easy Way https://portswigger.net/research/finding-dom-polyglot-xss-in-paypal-the-easy-way
PortSwigger Research
Finding DOM Polyglot XSS in PayPal the Easy Way
Introduction Finding DOM XSS can be tricky when it's buried in thousands of lines of code. We recently developed DOM Invader to help tackle this using a combined dynamic+manual approach to vulnerabili
Bug Bounty Promotion: SQL Injection Bugs on All Verizon Media Assets
https://www.verizonmedia.com/insights/promotion-public-004
https://www.verizonmedia.com/insights/promotion-public-004
Yahooinc
Yahoo Advertising | Digital Online Advertising Platforms
Reach your online audience across every screen with Yahoo Advertising digital advertising platforms. Learn more about our DSP solutions.
API Security Misconfiguration Leads to tons of PII data Leakage
https://thevillagehacker.medium.com/api-security-misconfiguration-leads-to-tons-of-pii-data-leakage-fc57f1b9228
https://thevillagehacker.medium.com/api-security-misconfiguration-leads-to-tons-of-pii-data-leakage-fc57f1b9228
Medium
API Security Misconfiguration Leads to tons of PII data Leakage
Introduction
Taking over Uber accounts through voicemail
https://blog.assetnote.io/2021/06/27/uber-account-takeover-voicemail/
https://blog.assetnote.io/2021/06/27/uber-account-takeover-voicemail/
Breaking Reset Password Logic To Get Account Takeover Without User Interaction
https://sapt.medium.com/breaking-reset-password-logic-to-get-account-takeover-without-user-interaction-f241fefe12e7
https://sapt.medium.com/breaking-reset-password-logic-to-get-account-takeover-without-user-interaction-f241fefe12e7
Medium
Breaking Reset Password Logic To Get Account Takeover Without User Interaction
Hello guys👋👋 ,Prajit Here from the BUG XS Team. So, in this write-up I will be sharing the method that how I broke reset password logic…
GitLab triages bug bounty-reported flaws with latest release
https://portswigger.net/daily-swig/gitlab-triages-bug-bounty-reported-flaws-with-latest-release
https://portswigger.net/daily-swig/gitlab-triages-bug-bounty-reported-flaws-with-latest-release
The Daily Swig | Cybersecurity news and views
GitLab triages bug bounty-reported flaws with latest release
CSRF and denial-of-service vulnerabilities extinguished
Slack integration setup lacks CSRF protection
https://hackerone.com/reports/170552
https://hackerone.com/reports/170552
HackerOne
HackerOne disclosed on HackerOne: Slack integration setup lacks...
Details:
**Summary:**
Cross-site Request Forgery in the `Integrations` (https://hackerone.com/[YOUR_TEAM]/integrations) feature for teams.
**Denoscription (Include Impact):**
The `Integrations`...
**Summary:**
Cross-site Request Forgery in the `Integrations` (https://hackerone.com/[YOUR_TEAM]/integrations) feature for teams.
**Denoscription (Include Impact):**
The `Integrations`...
Removing parts of URL from jQuery request exposes links for download of Paid Digital Assets of the most recent Order placed by anyone on the store! https://hackerone.com/reports/1044285
HackerOne
Shopify disclosed on HackerOne: Removing parts of URL from jQuery...
A report from @superbsic showed that it was possible to download the latest digital purchased order attachment for stores that have the Digital download app installed, by setting the checkout_token...
Add new managed stores without permission https://hackerone.com/reports/1167753
HackerOne
Shopify disclosed on HackerOne: Add new managed stores without...
Details
A staff member who has permission to add, archive and unarchive development stores as shown in managedStoreA.png can also add new managed stores. I can't tell if the issue I pointed out in...
A staff member who has permission to add, archive and unarchive development stores as shown in managedStoreA.png can also add new managed stores. I can't tell if the issue I pointed out in...
Params — Discovering Hidden Treasure in WebApps
https://kathanp19.medium.com/params-discovering-hidden-treasure-in-webapps-b4a78509290f
https://kathanp19.medium.com/params-discovering-hidden-treasure-in-webapps-b4a78509290f
Medium
Params — Discovering Hidden Treasure in WebApps
Hey Guys!! What's Going on? 👋 I was thinking of Tweeting about parameter discovery in web apps lately, however, while I was composing the…
Account Takeovers — Believe the Unbelievable
https://blog.niksthehacker.com/account-takeovers-believe-the-unbelievable-bb98a0c251a4
https://blog.niksthehacker.com/account-takeovers-believe-the-unbelievable-bb98a0c251a4
Medium
Account Takeovers — Believe the Unbelievable
I had set a goal for myself to look for only account takeover issues for a certain period of time. Fortunately, I did accomplish my goal…