Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @0xdeadpool
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @0xdeadpool
-
Prikvačeni tweet
Finally wrote a blog. An old issue in SpringBoot which could allow RCE. Inspired from
@secalert blog.https://deadpool.sh/2017/RCE-Springs/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Quickly get the ASN of an IP address, along with the associated company name and location: curl http://ipinfo.io/ <ip> This is a great way to confirm ownership of an IP/domain. It also is a great way to services that might be in use (AWS/Azure/Cloudfront/Akamai, etc.)pic.twitter.com/0Ng0qEQIbt
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Shopify disclosed a bug submitted by fransrosen: https://hackerone.com/reports/422944 - Bounty: $15,000
#hackerone#bugbountypic.twitter.com/saUzCvh0uB
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Today I presented a rough idea of a (brand-new?) data exfiltration technique with regular expression injection and timing attack at OWASP Night (Japan). Enjoy!
#owaspnight#owaspjapanhttps://speakerdeck.com/lmt_swallow/revisiting-redos-a-rough-idea-of-data-exfiltration-by-redos-and-side-channel-techniques …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Tushar proslijedio/la je Tweet
Our first blog post of 2020 is out! Learn about how we discovered a heap overflow in the F-Secure Internet Gatekeeper, which leads to unauthenticated RCE https://blog.doyensec.com/2020/02/03/heap-exploit.html …
#infosecpic.twitter.com/z5ZUEETMnp
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Some
#bugbounty hunters made over €50.000 in bug bounties with this simple trick.
Thanks for the #BugBountyTip,@rez0__!pic.twitter.com/z9sPFJTNqV
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
-API TIP:26/31- Looking for BOLA (IDOR) in APIs? got 401/403 errors? AuthZ bypass tricks: * Wrap ID with an array {“id”:111} --> {“id”:[111]} * JSON wrap {“id”:111} --> {“id”:{“id”:111}} * Send ID twice URL?id=<LEGIT>&id=<VICTIM> * Send wildcard {"user_id":"*"}
#bugbountytipsPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
New blog post: A Less Known Attack Vector, Second Order IDOR Attackshttps://link.medium.com/okQ4s0yss3
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
I wrote a secret scanner tool and published it under my employer's GitHub org. Since I don't have much Twitter reach I appreciate any RTs! It currently will scrape Git, S3, and GDocs for secrets, and written in Rust for high performance.https://github.com/newrelic/rusty-hog …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
if you find 403 Forbidden while testing. Try X-Original-URL and X-Rewrite-URL Headers to bypass restrictions
#Collectedpic.twitter.com/CA3ZYhRy0A
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
The new Shodan has a feature to query domain which lists all DNS records as well as subdomains. https://beta.shodan.io/domain/google.com … Now, it's even easier to extract domains from Shodan, I guess.
#TILPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Here my GitHub with many scripts useful for red teamers - Enjoy! https://github.com/BankSecurity/Red_Team …
#redteamHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Check out my bug bounty tip for
@Intigriti! Often helps me escalating low severity IDORs to crits!https://twitter.com/intigriti/status/1217794181982302208 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
lsassy 1.0.0 is finally out !
Remotely dump #lsass **with built-in Windows tools only**, procdump is no longer necessary
Remotely parse lsass dumps to extract credentials
Link to #Bloodhound to detect compromised users with path to Domain Admin https://github.com/Hackndo/lsassy pic.twitter.com/vljW7swZGr
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :)https://spaceraccoon.dev/remote-code-execution-in-three-acts-chaining-exposed-actuators-and-h2-database …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
If you run Citrix in your network you *really* need to read this. A decent
@shodanhq dork to find systems is here: https://beta.shodan.io/search/facet?query=http.waf%3A%22Citrix+NetScaler%22&facet=org … Every single system I've spot checked so far has been vulnerable; this will burn people for a while. Take steps to defend yourself ASAP.https://twitter.com/craigtweets/status/1214974955835854848 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Not sure what search filters are available? Check out our new filter reference page: https://beta.shodan.io/search/filters pic.twitter.com/bUJX1D8ChQ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je Tweet
Recently I was on a pentest and needed to manage Active Directory groups from Linux to achieve privilege escalation. If you find yourself in a similar scenario, this is what you can do:https://www.n00py.io/2020/01/managing-active-directory-groups-from-linux/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Tushar proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Tushar proslijedio/la je Tweet
Have reproduced Citrix SSL VPN pre-auth RCE successfully on both local and remote. Interesting bug!https://www.tripwire.com/state-of-security/vert/citrix-netscaler-cve-2019-19781-what-you-need-to-know/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
Thanks for the
