My friend made a very interesting disclosure while searching for vulnerabilities. I personally couldn't believe it when I saw that he was able to make Self-XSS in a Ruby on rails application to RCE. Deserves time to read 👇
https://t.co/mNblQFTzch
@matt_ruwe Hey @matt_ruwe can you reach out? I have a topic related to pointing poker I'd like to discuss via DM but I can't send you a message.
Thank you :)
XSS to ATO from 2019 (not by me) - got duped in March 23. Resolved in October 23, still working. Reported, triaged, rewarded, closed in December 23. Still working right now. Re-reported and stated that a fix has never been deployed🤯What are they doing?
#hackerone#xss#bugbounty
Found a RXSS to full account takeover last year March => dupe from 2019. Initial report resolved in October. Payload still working in December => reported, triaged, rewarded, resolved in February 2024. Payload still working now. Report again?
#bugbounty#xss#hackerone
@Krevetk0Valeriy@monkehack@Hacker0x01 Same for me, also had some programs where resolved reports for single scope entries exceeded the 100% like having 560% 🧐
Found an endpoint like target .com/foo/ => forbidden
Added ..;/ and a tomcat landing page of tomcat 7.0.57 appeared.
/manager/html and other ones are basic auth protected.
What would you do next?
#bugbounty#hackerone#tomcat
Any ideas to exploit this SQLi? Single quote to escape;
OR 1=1 -- returns 3mb of data (not critical)
ORDER BY says 17 columns.
chr() works but SELECT and UNION SELECT arent working.
IF/CASE and sleep functions trigger the error.
Errors do not differ.
#bugbounty#sqlinjection
Program states that every RXSS is medium unless you can show significant operational or financial impact. Do you think ATO through password change should be considered as this?
#xss#ato#bugbounty
Reported an XSS to ATO in March this year, which was a dupe from 2019 🫣
The initial report is now resolved but xss still works.
Report again?
#bugbounty#xss
Just found a post auth 1-click xss which allows exfiltration of clear text password and send it to attacker endpoint.
Program says xss is OOS because of akamai is not blocking it...
What would you do?
#bugbounty#xss#hackerone
Friends from Ukraine, Belarus, Russia: if you need to bail out, DM me for help. I have opened all roles and levels in my team for blue card / relocation support so that I can leverage my hiring plan as the strongest resource available to me to build exit strategies & safe places
Der neue #LucaApp Hack ist eine Gefahr für Nutzerinnen und Gesundheitsämter.
Werden die Ministerpräsidentinnen endlich Konsequenzen ziehen?
Oder kommt nexenio/culture4life WIEDER damit durch, zu leugnen?
Es reicht langsam.
https://t.co/4PVQspcQOF
I'm *extremely* excited to announce https://t.co/DQiFfTdVj5 - The Responsive Design Browser 🎉 🎊 🔥 🥁 🎺 🥳
YES! An actual browser for designers and developers 🤩
Tons of amazing features and even more coming soon! 😎
3 random people who RT will get a lifetime license 👌 🎫
@stangomat@SalesforcePetr@rsoesemann And text type for formatting purpose after blurring. It looks like that FF gets confused when changing types.
I just left it as a lightning:input but without any formatter 💁♂️
In chrome it works well...
https://t.co/2bI8VYeO9v
Thats the bug tracking link the support sent me... 2/2
@stangomat@SalesforcePetr@rsoesemann This seems to be an issue in firefox. I opened a case in the past and they told me, they wont fix it because it's not "lightning related". In the background the lightning component changes input type from number to text. Number type when user focuses input field... 1/n
Achtung! @ManfredWeber will die Abstimmung über #Artikel13 & die Urheberrechtsreform auf nächste Woche vorverlegen, um den #SaveYourInternet-Protesten zuvorzukommen! Wir brauchen einen öffentlichen Aufschrei, um das zu stoppen. Für die EU-Fraktion der SPD entscheidet @UdoBullmann
Today we are publishing that we had access to 7 water purification plant in Germany. We reported the issues to the German BUND CERT @BSI_Presse and the vendor of the control software. (1/2)