Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @Ajay_kulal
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @Ajay_kulal
-
Prikvačeni tweet
Thank you so much
@Hacker0x01 and@MonkeyBanking
#sonya7ii#macbookpro2019pic.twitter.com/tDTpxXIu4X
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Ding dong, SHA1 is dead. https://sha-mbles.github.io/
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
It's not just theories
https://www.ambionics.io/blog/php-mt-rand-prediction …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
CVE-2019-10758 post-auth Remote Code Execution in mongo-express < 0.54.0 via endpoints that uses the `toBSON` method however there are lots of no-auth mongo-express ... shodan: https://www.shodan.io/search?query=Mongo+Express … poc: https://github.com/masahiro331/CVE-2019-10758 …pic.twitter.com/zp7EK2cmu3
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Why not step into the next decade with WAF bypasses? Here are some gifts.
- Imperva
<a69/onclick=write()>pew
- DotDefender
<a69/onclick=[0].map(alert)>pew
- Cloudbric
<a69/onclick=[1].findIndex(alert)>pew
Happy 0x32303230.
#infosec#bugbounty#bugbountytipspic.twitter.com/74KGzwMqME
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Just posted From checkra1n to Frida: iOS App Pentesting Quickstart on iOS 13 - to be followed up with a second writeup on bug I've found with these tools.https://spaceraccoon.dev/from-checkra1n-to-frida-ios-app-pentesting-quickstart-on-ios-13 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Ajay Kulal proslijedio/la je Tweet
On September 29, 2017, Discuz! fixed a vulnerability that would cause front-end users arbitrarily deleting files. Knownsec 404 Team have made recurrence and posted an analysis about it. Learn more on Seebug Paper: https://paper.seebug.org/1101/ and Medium.https://medium.com/@knownsec404team/discuz-x-3-4-arbitrary-file-deletion-vulnerability-analysis-5eb4b7212244 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
A 10 million euro GDPR violation fine for failing to update phone call authentication protocols. This is huge. Hopefully this example jump starts more companies to secure their phone support!https://twitter.com/svblxyz/status/1204037296263184384 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Let's say that during a pentest you discover requests to <name>.azure-api.net
Congratulations it means that you found an API hosted by Azure API Management!
The root doesn't reveal anything but you can go to <name>.portal.azure-api.net to see its documentation (& more!)
pic.twitter.com/a8ZBIk4xsj
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Hi,
#hackers and#bugbounty. I'm building a test tool for WebSocket Connection Smuggling, and I don't know what else to add. I made basic check feature, and will be put in a code that scan the internal port(or ip range?)s through Smuggling. https://github.com/hahwul/websocket-connection-smuggler …#bugbountyipsPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
#bugbountytip huge productivity boost needed? Go and check out https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/ … in case you use Firefox for testing. This eases multiple account / tenant testing by a mile. Shoutout to@infenet, who showed me this add-on in the first place!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Follow this step-by-step guide to properly test for
#XSS… Like a#KNOXSS! https://brutelogic.com.br/blog/testing-for-xss-like-a-knoxss/ … by@rodoassis@brutelogicHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Quick and dirty way to find parameters vulnerable to LFI & Path Traversal & SSRF & Open Redirect: Burp Search > Regex \?.*=(\/\/?\w+|\w+\/|\w+(%3A|:)(\/|%2F)|%2F|[\.\w]+\.\w{2,4}[^\w]) Suggestions are welcome.pic.twitter.com/E0nEDFeUaM
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
if you are interested in finding 0-days vulnerabilities from reading codes, here are some articles that I wrote about how I managed to find 0-day RCEs from static code analysis. https://shells.systems/category/static-code-analysis/ … I hope that will help you all! More to come soon ;)
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Wonderful read on JWT!https://research.securitum.com/jwt-json-web-token-security/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Are you ready for the 11th edition of
@nullcon? We present to you the inspiration for this edition - "Vaishyanath – The Protector." He is the 11th incarnation of Shiva. Here is a small blog post on the explanation of#Vaishyanath: http://bit.ly/2XFom5t#Nullcon#Nullcon2020pic.twitter.com/UTz8SZvpyG
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
1) Call me vulnerable because you make my Heartbleed. 2) Thank you for giving me the creds so I could priv esc to your heart 3) Don't worry girl you are not a dupe, you are my first
#BadBugBountyPickuplinesHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
Shodan is turning 10 :) Can't believe it's already been a decade. I'm excited as ever to be working on something I love and thank you to everybody that's supported the project over the years:https://blog.shodan.io/happy-10-year-anniversary/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
New #WebAssembly security blogpost
Do you know that it's pretty easy to create an HTML/JS/Wasm module polyglot?
Those polyglot files are consider as valid:
HTML/Javascript files
WebAssembly modules
https://webassembly-security.com/polyglot-webassembly-module-html-js-wasm/ …
Kudos to @angealbertini for the help ;)Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Ajay Kulal proslijedio/la je Tweet
I M P O R T A N T This is a collection of nearly all known attack techniques against JWT. It also includes a tool to automate all checks and even a JWT primer.https://github.com/ticarpi/jwt_tool/wiki#menu …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
