This awesome 'FFuf Advanced Tricks' article by @noraj_rawsec needs a shoutout. I created my own FFuf script based on his tricks, and here is the result. #BugBounty
https://t.co/5l4RMlmhV5
@infosec_au Just my opinion, they should. If you are a respected company, when you implement a third-party into your infrastructure you should do a very detailed security check of it. Again, my personal opinion, but I don't mind if they don't pay for vulnerabilities in tp, it's their right
What people seem to miss:
The #Log4Shell vulnerability isn't just a RCE 0day.
It's a vulnerability that causes hundreds and thousands of 0days in all kinds of software products.
It's a 0day cluster bomb.
📈 How to find client-side prototype pollution at scale
Great work by @black2fan, @s1r1u5_ + more
They found:
* 18 vulnerable libraries
* Reported ~80 bugs to vulnerability disclosure programs
* Found more than 1,000 vulnerable websites
#bugbountytips
https://t.co/3NU7jcnO64
In August I will have to arrive in Vegas to present at #Defcon 29.
Is anyone willing to help me financially with my trip to Las Vegas? I could mention in one of the slides about the company/person and thank him personally for helping me financially to get there.
Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies
👇Check the thread after reading for a few bonus facts👇
https://t.co/00acKS0ur3