BugPoC is a platform to build and share proof-of-concepts for Bug Bounty Submissions, PenTest Deliverables, & Red Team Reports. Create your free account today at https://t.co/ZmvEkdOOgz
A group of MacOS vulnerabilities—fixed by Apple at the end of last year—could allow an attacker to "punch a hole" in your Safari browser, granting them access to your online accounts, to turn on your mic, or even take over your webcam. 😳 https://t.co/iP7IkDgbMN
Great research once again from Ryan Pickren for those looking for Apple bugs: Gaining unauthorized camera access via Safari UXSS
https://t.co/SP8duGpq8T
Got SSRF/LFI using Open Graph Protocol , Server was parsing thumbnail using og:image property , Crafted a page by putting <meta property="og:image" content="file:///etc/passwd"/> to pull local file, Similar approach used to solve @bugpoc_official CTF⬇️
#bugbounty#bugbountytips
Want to learn how to chain an Encryption Oracle + SSRF + Dir Traversal + Heapdump? Check out this great write-up by @dunglt140150 about our latest CTF! 📝
Huge thanks to all hackers that made write-ups! More CTFs coming soon! 🪲🔨
https://t.co/oPjhzjsvGY
New video! I just made a walkthrough of @bugpoc_official's Doggo CTF in partnership with @amazon's security team. Some fun with device fingerprinting, a path traversal, and more! https://t.co/v20OSyn6QN
BTW the CTF is still up, if anyone wants to give a try!
Thanks for the fun memory leak challenge @bugpoc_official@NahamSec!
Wrote a thing or two on how to approach & solve the challenge, alternative solutions, and shared some tools/tips as well. Enjoy! :)
https://t.co/ZEld3hUzhQ
Huge THANK YOU to all the hackers that participated in our latest CTF!
Congrats to the following raffle winners: @RobinZekerNiet@TechBrunchFR@Akshanshjaiswl@y_sodha Check H1 for a $250 prize!
Don't forget to publish blog write-ups before 05/05 10pm EDT. Our fave gets $250!