I earned $1,000 for my submission on @bugcrowd https://t.co/Y67SgbVzuI #ItTakesACrowd
Vulnerability: Account Takeover via Content URI Trust Confusion
:)
I earned $1,000 for my submission on @bugcrowd https://t.co/Y67SgbVzuI #ItTakesACrowd
Vulnerability: Authentication Bypass + In-App UXSS via Exported Deep Link Activities
Today I released a new article called "Data Exfiltration with Style (CSS)". It expands on a talk I gave at an event and a community meetup. I hope you enjoy it! :)
https://t.co/Z47g96NGAP
@K4L1_FS@r0nycosta Sobre a detecção, o artigo fala que não da pra detectar de forma nativa (Event Log Viewer, por exemplo), e sim temos que usar soluções de monitoramento que suportem o tráfego LDAP. Ele fala sobre o Netwrix Threat Prevention já que o artigo é deles, mas devem haver outras opções
@K4L1_FS@r0nycosta Analisando o código do repositório, ele aparentemente usa o mecanismo de "LDAP Ping" do Active Directory. No fim, ele faz a seguinte pesquisa:
(&(NtVer=\06\00\00\00)(AAC=\10\00\00\00)(User=user))
E compara os hex da resposta, onde "17 00" se existe e "19 00" se não.
A little tip if you want to start two emulated devices with Objection and don't know how. Since Objection does not have a flag for specifying the device, you can forward the 27042/3 ports and start multiple Objection instances.
@jeetbhdr@fr4vian That’s not my point. You can read in my Tweet there is a good “initial reason” to report to VDPs. Hunting in public programs can be a bit harder, so, if you want to start to get some private programs, go to VDPs and make sure to send good reports and wait for some invites.
Giving bug bounty another chance, let's see how it goes. All reports are for public programs since I don't have access to private programs yet xD
2 mobile
2 web
@pqcorvo No início do post está bem exposto que era em um programa de bug bounty, acho que faltou leitura da sua parte.
Uma dúvida, o correto então é criar contas falsas em instituições financeiras então? Não entendi a ideia ainda.