Also, I've written this one more like a story to try and keep it engaging without losing technical detail. Happy to receive constructive feedback on whether you feel that works or just makes it long-winded.
-
-
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
After following you guide i found a program that might be vulnerable to this, after some testing i finally got a interesting response: HTTP/1.1 416 Requested Range Not Satisfiable X-Cache: HIT X-Cache-Hits: 82 But when i went to another browser and browse it i got code 200??
-
The User-Agent might be in the cache key. Make sure you read and understand https://portswigger.net/research/practical-web-cache-poisoning … first
Kraj razgovora
Novi razgovor -
-
-
Awesome post. I was testing an application which uses cloudfront, your trick worked like charm. Thanks
@albinowaxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
I had an eye-opening meeting regarding DoS a few years ago. I reported SQLi and it was nothing for them. Until I showed that you can DROP the database causing downtime. That got them scared since that meant a measurable loss of money and lots of angry calls from clients
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
It is interesting that DoS/DDoS attacks are considered 'unsexy' One of the core tenants of security is Availability. If these attacks actually occur, in many cases it causes severe losses, seems odd to downplay it as 'just DoS'
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
And for SaaS/PaaS targets, DoS vulnerabilities can quickly become very expensive if it breaks the SLA they have with their customers. Making it's worth a perusal of the company's T&Cs for their service offering before you write up your Business Impact statement.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
I was able to exploit a CVE last month that caused a DDOS using the range header...unfortunately they didn't accept it because it was a performance issue and not a security issue. Glad to see that some programs are opened to dos disclosure.
-
Thanks for the share!
Kraj razgovora
Novi razgovor -
-
-
Thanks for this James
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.