Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @D4Vinci1
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @D4Vinci1
-
Prikvačeni tweet
Happy to announce the release of
#One_lin3r version 2. One-lin3r now got a rewrote with a lot of new features like installing it from PyPI, copying the liner automatically, variables and more. Also, it now has 155 liners instead of 33 liners. Check it out: http://github.com/D4Vinci/One-Lin3r …pic.twitter.com/9rJRg5qofW
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
My new report about (Facebook page admin disclosure) https://bugreader.com/kbazzoun@132
#facebook#bugbounty#bugreaderHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Reflected XSS https://link.medium.com/j1cgHbZpq3 https://link.medium.com/q9eeokp2J3 https://link.medium.com/5zdO3gPEw3 https://link.medium.com/vwwEcNQEw3 https://link.medium.com/TH0sHaq2J3 https://link.medium.com/njXx6sq2J3 https://victoni.github.io/bug-hunting-xss-on-cookie-popup-warning … https://gauravnarwani.com/cookie-worth-a-fortune … https://link.medium.com/bx6lLPq2J3 https://link.medium.com/3khM76q2J3
#bugbountyHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Hacker tip: when you’re looking for IDORs in a model that references another model, try storing IDs that don’t exists yet. I’ve seen a number of times now that, because the model can’t be found, the system will save the ID. (1/2)
#TogetherWeHitHarderPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Did you know that the address '<a@b.com>c@d.com' when given to SES will send an email to a@b.com? this could lead to interesting exploit scenarios with some email parsing libraries/code https://nathandavison.com/blog/exploiting-email-address-parsing-with-aws-ses …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
#BugBountyTip time: combine Arjun from@s0md3v with BurpIntuder to bruteforce parameter values. I once got "?debug" as a valid parameter and got "on" as a good value which disclosed juicy information helping me chain bugs to a P1. Final: "?debug=on"#bugbountytips#pentest RT & LHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Cross-Site Websocket Hijacking bug in Facebook that leads to account takeover https://ysamm.com/?p=363
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
#BugBountyTip time: when you see a POST request made with JSON, convert this to XML and test for XXE. You can use "Content-type converter" extension on@Burp_Suite to do achieve this!#bugbountytips#infosec#hacking#pentest#pentesting#bugbounty RT and Follow, book coming!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
#BugBountyTip time: I've got a RCE by using this tip: while testing for malicious file uploads, if .php extension is blacklisted you can try .PhP , .php5 and .php3 Sometime this fools the backend and you get shell! RTs & comments are appreciated. Follow#bugbountytips#pentestHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Figuring out source of a file
For example, If you download an image from Reddit, it will be saved as [a-z0-9]{13}.jpg
Below is a list of such schemes that I made under 15 minutes: https://github.com/s0md3v/Dump/blob/master/static/filename-fingerprinting.md …
It's kinda useless but it's 5 AM and I just had to tweet it
pic.twitter.com/qcWas4YEYJ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Excellent write up of the Remote Desktop Protocol (RDP) Gateway vulnerabilities Microsoft patched this week. If you have this in your environment, especially Internet facing, patch now. Previous called Terminal Services. CVE-2020-0609 CVE-2020-0610https://www.kryptoslogic.com/blog/2020/01/rdp-to-rce-when-fragmentation-goes-wrong/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Time for a new
#bugbounty tip! When I sign up to a website/newsletter/reset password, I look at the website which hosts the logo/image in the email I receive. This led me multiple time to insecure AWS S3 buckets and scope expansion.#bugbountytip#bugbountytips#infosec#hackingHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
So you believe UUID's are a sufficient protection against IDOR's? Think again!
Thanks for the #BugBountyTip,@securintipic.twitter.com/zx5Xn7iDrE
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Ghidra Script that sets the names for missing function names by looking for relevant patterns in the binary! Hope that will help you too :) https://github.com/alephsecurity/general-research-tools/tree/master/ghidra_scripts …pic.twitter.com/YmgTMhLJXR
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Some dude who works at $localSecurityCompany just lectured me on bus opsec because he could tell by the labels on my laptop I was a hacker. My dude... it's when you see me with a BLANK computer you need to be suspect. Bad guys don't come with warning labels.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
My great friend Ahmed Khlief wrote an article about recreating MuddyC3 that used before by MuddyWater Iranian APT group. https://shells.systems/reviving-leaked-muddyc3-used-by-muddywater-apt/ … The article is a great opportunity for both red teamers and blue teamers to understand more about how the threat groups acting!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
I just released some of my PoCs! IDOR: https://youtu.be/3hJaxmiSzO4 Stored XSS: https://youtu.be/pwLG7tAGO08 Stored XSS: https://youtu.be/fnW0w2VYT2I RXSS: https://youtu.be/IC43MzAkC7E RXSS: https://youtu.be/DZxMB_KOoMk RXSS: https://youtu.be/L5isQP28o3M RXSS: https://youtu.be/CaoAh2CXyr0
#GeneralEG#BugBountyHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
I just published "Hunting Good Bugs with only <HTML>" https://link.medium.com/oTrMsKEM72
#bugbounty#infosec I hope you enjoy this post!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
One of the scarier bugs I’ve found: with Microsoft’s go-ahead & after many hours spent, I’m excited to finally publish this writeup and PoC!
https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
A while back I made a Discord server, but got tied up with real life stuff and couldn't put in the time to moderate it. When I came back it had gotten super toxic, but the toxic members were also smart and extremely active. 1/?
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Karim Shoair proslijedio/la je Tweet
Resources-for-Beginner-Bug-Bounty-Hunters : A list of resources for those interested in getting started in bug bounties https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters … cc
@NahamSecHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.