@MADRID he puesto un aviso en la aplicación de Madrid móvil, que hay una señal tirada en el suelo, y me han denegado diciendo que "no consideran necesario" arreglarlo.
La verdad, hacéis un trabajo de puta madre cuando queréis .
@ComunidadMadrid
¡Lorenzo Martínez será el protagonista del próximo episodio de #Hat2Hack! 😎
Hablaremos de los análisis forenses en #ciberseguridad, las #ciberestafas más habituales, entre otras cuestiones de lo más interesantes 🔝
¡El 24 de Noviembre disponible! 😊
#podcast#ciber
¿Conocéis la Metáfora del Castillo? 🏰
María Rojo, en el próximo episodio de #Hat2Hack, nos lo explica y en qué situaciones ha tenido que ponerlo de ejemplo 😊
El 15 de septiembre 🗓️ lo tendréis disponible en en #YouTube, #Spotify e #iVoox 🎧
#Ciberseguridad#Pegasus#podcast
¡Miguel Angel De Castro visita #Hat2Hack! 😎
El 1 de septiembre tendréis disponible el próximo episodio en el que hablaremos de cosas tan interesantes como la #IA, #Pegasus o casos históricos como el #WannaCry 😳
¡Estad atentos! 🎙️
#Ciberseguridad#Podcast#ciber
When testing for SSRF, you’ll often hit blocklist errors when targeting localhost or cloud metadata hosts.
Here are some bypass techniques that consistently work for me:
- Use a 303 redirect to an internal host — many apps follow redirects without validation & convert POST → GET
- DNS tricks like https://t.co/pshzbZl7tT (resolves back to localhost)
- Append @blacklistedDomain after a whitelisted URL/domain
- Add # at the end of the domain if the backend appends paths/params when making request.
Just published my first blog post "Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover"
You can read the full write-up here:
https://t.co/pfLArv8zUu
¿La gente de ciber somos #Hackers? 🥷
En el primer episodio de #Hat2Hack se plantea si nos podemos autodenominar Hackers 🧐 y si es una filosofía de vida 😌
¡Estrebamos el 18 de agosto y podréis reflexionar sobre este tema! 🎙️
#Hat2Hack#Ciberseguridad#Podcast#ciber
This might be one of the most exciting things @Xbow has exploited recently in a Bug Bounty program.
Not just because of its impact, but because of the steps required to uncover and exploit the vulnerability.
#bugbounty#hacking#ai
Back to hacking PayPal after some time off, mass PII exposure this time. Shoutout to h1_analyst_alexander, always professional and on point.
Even when everything looks secure, there's always something to find.