@Th3G3nt3lman 5️⃣ Write-up: AWS Document Signing Security Control Bypass
Ozgur shares a cool way of abusing application logic to bypass AWS Document Signing!
https://t.co/4bQM414fPb
@GodfatherOrwa@net_code 3️⃣ We Hacked Apple for 3 Months: Here’s What We Found
A classic write-up by 5 talented researchers that briefly talked about their experience hacking Apple for 3 months!
https://t.co/ZljiBJd489
@triplewhale
I'm bringing attention to a critical issue. I reported a vulnerability exposing sensitive org info over a year ago, with @Ariel's commitment to a reward. since then. No reward response. I'm giving you a chance to rectify this. Reach out, or face the consequences.
@salesboomCRM@SalesboomCloud
Hello team,
I found a CRITICAL vulnerability in one of your digital asset and I tried to contact you guys via email but not getting any response. Kindly reach out to me at [email protected] at your earliest convenience.
Thank you
A group of children miraculously survived the Holocaust at the Al-Ahli Arab Hospital after the Nazi Israeli occupation bombed the hospital, resulting in the deaths of 500 martyrs and the injury of 600 other civilians, most of whom were children and women.
XSS -> ATO Escalation Brain Dump:
* Change email -> password reset
* Change password
* Change phone -> SMS password reset
* Change security questions
* Add SSO login (login with GitHub, ect)
* Force logout -> Session Fixation
* Steal session token via non-HTTP only cookie
* Steal session token via insecure embed in page
* Steal API key for application
* Add admin user to organization
* Hijack oAuth flow and steal code
* Steal SSO code to adjacent app, then reverse SSO back to main app
* Add authentication method (SMS, email, etc)
* Gain access to refresh token for JWT or session
Got any more?
Found my first RCE on a bb target, probably the best one too :)
HTMLi to RCE 🚀
If the backend is python and the application offers a pdf render endpoint there are high chances that they are using reportlab (very popular) to generate those pdfs .
POC: https://t.co/L3Xf8iUnOV
I've earned more than 5-figure bounties from sensitive links, sent via email, that were leaked without any user interaction. Surprisingly, the leaks came from the very security vendors that were supposed to protect the victims.
Curious how this happens? 👇
#BugBounty
Vulnerability accepted! @StateDept
Vulnerability: Reflected XSS
Tip: Try second or third level URL encoding if application won’t allow you to use simple XSS payload.
#infosec#CyberSecurity