That was fun. I bypassed a @OpenAI ChatGPT /mnt/data restriction via a symlink, downloaded envs, Jupyter kernels' keys, and some source code from there. Reported via @Bugcrowd and got not applicable! Now this issue is fixed (in like an hours after my report).. Is it how it should be? Asking for the community here. Screenshots attached.
TurkuSec September Meetup!
Date: 14.9.2023
Time: 17:45 – Onwards
Venue: SparkUp Turku (Tykistökatu 4B)
“Securing 5G networks with Federated learning and GANs” by Rayyan Hassan
“What is CTI?” by Lauri Vakkala
Join us! More info: https://t.co/O6oSi6goXx
How do you fuzz code that cannot be instrumented, e.g. on an embedded system? It turns out you can use GDB for that!
👉 Check out our upcoming “GDBFuzz” @issta_conf paper at https://t.co/UhYHZOjDx3
👉 GDBFuzz is available as open source at https://t.co/qDjxVIzH3H
Need to bypass the JWT signature? Kid param injection + directory traversal = signature bypass
Vulnerable apps using 'kid' for key retrieval might allow attackers to force a predictable key file (e.g. static file or /dev/null)🔓 Crafted malicious tokens signed w/ known key
@OsmoSoininvaara Mitään teknistä estettä en näe sille, että loppukäyttäjä ei voisi applikaatiolla ostaa mielivaltaisen monta minuuttia kerrallaan voimassaolevaa lippua.