Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @rawsec
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @rawsec
-
Prikvačeni tweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Sigh. It's 2020. Crypto exchange
@kucoincom just awarded me a $28.49 bounty for an unconditional XSS vuln on their main domain. (via 3rd party component but still...) A little deceitful to call that a#bugbounty program
@gan_chun$KCSHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Know someone who needs a Titan security key bundle from Google? Got that promo mail where someone gets a free bundle if I refer them to Google's Advanced Protection Program
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Arbitrary code execution vulnerability in Vim < 8.1.1365 and Neovim < 0.3.6 via modelines.
Also, why you should not use Vim with default config, or cat without -v. https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md …pic.twitter.com/QgOx7UWyYpHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
My write-up for Hackover CTF "cyberware" challenge. Using dir trav and manually obtaining packfiles from git meta dir. Was a nice little peek into git internals.https://security.meta.stackexchange.com/a/3087/9538
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Where's Bobby Tables when you need himhttps://twitter.com/StackStatus/status/1047917377516687360 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Write-up for
@DragonSectorCTF Nodepad web challenge. :) XSS + SQLi + CSP bypass. That's some neat challenge design! https://security.meta.stackexchange.com/a/3076/95381#DragonCTFHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yay, finally solved Nodepad web challenge with team secse for
@DragonSectorCTF. That one was super well designed. :) Now time for some sleep#DragonCTFHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
At my bank, a wire transfer requires PIN and TAN. Fine. But as it turns out, to close your account, you can just send in a signed form including the account number you want the balance transferred to. No auth, not even a confirmation call.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Apparently, the security of
@deutschetelekom is so abysmal, their bug bounty program explicitly *excludes* RFI, LFI, and XSS.https://www.telekom.com/en/corporate-responsibility/data-protection-data-security/security/security/closing-security-gaps-360054 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Yay, after 8 months,
@StackExchange finally fixed an XSS bug on http://openid.stackexchange.com . More vulns incoming. :)Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Awesome, my bank sending my account information as an encrypted PDF... and the key is my five-digit ZIP code.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Fascinating how many people casually backdoor their projects.
#githubdorks https://github.com/search?q=eval+%24_REQUEST&type=Code …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Great write-up of the "Title Case"
#SHA2017 CTF challenge! http://hugodelval.com/writeup/2017%2008%2006%20-%20SHA2017/Title%20Case%20-%20PWN%20-%20200pts …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Really want to see a write-up for the
#SHA2017 "Title Case" CTF challenge. That was one annoying Python jail.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Excited to play the
#SHA2017 CTF. Hoping for some interesting challenges. :)Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Can you solve this 2nd mini XSS challenge, too? <?php echo file_get_contents(str_replace(['/', '.'], '', $_GET['q'])); ?>
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A small write-up for the Geokitties v2 challenge and a few words on charset sniffing.
#GoogleCTF https://github.com/numirias/ctf/blob/master/writeup-google-ctf-2017-geokitties-v2.md …pic.twitter.com/i5J2bEOOMa
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Can you solve this mini XSS challenge? <?php header('Content-Type: text/html;charset=utf-8'); echo preg_replace('/<\w+/', '', $_GET['q']) ?>
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
<?php