Most people's security strategy is wrong. Speak to me on Telegram @ pashovkrum about yours.
Btw, we are giving away 50 (yes, 50) monthly Claude Pro/GPT Plus plans to people who RT the main post and tag a fellow web3 developer below. Good luck, results on Monday🫡
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
https://t.co/SfxjuQ17gA
@Bugcrowd The filter uses urlparse(url).hostname.endswith(...), which can be bypassed because different libraries interpret "authority" differently.
The Payload
To hit a local service while bypassing the check: http://127.0.0.1#@internal.company.com
@intigriti The red flag is here:
format.json { render json: @users }
That returns all users as raw JSON, which can expose sensitive fields depending on the User model.
And the authorization is also badly designed:
unless current_user.admin? && request.format.html?
Since its launch a year ago, my web3 security company has both paid out to security researchers & profited >$1,000,000 USD. Secured Aave, Uniswap, LayerZero, Ethena.
We are celebrating with a giveaway. You need to like, retweet & comment. 4 winners, $500 each, 48hrs. Good luck🫡
#CRYPTO#FOREX#STOCK
📌 السلام عليكم قررت أعمل جدول للمحتوى كالتالي:
1️⃣محتوى يوتيوب بيكون مرة بالاسبوع يوم الأحد بيكون الحديث عن جميع الأسواق
2️⃣تحليل يومي للعملات بديلة و فوريكس و اسهم على تلغرام
3️⃣تويتر لتحديث فقط بتكوين و مؤشراته
📣تلغرام: https://t.co/IV2731HLBd