The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted!
https://t.co/mjzzM4S7k0
Part II: I found a bypass to Microsoft's fix using a Timing Attack to leak the Microsoft Event Registration database again! Here's the writeup: https://t.co/hgRoRiCptp #BugBounty#bugbountytips
We've published a new advisory regarding a circumstantial authentication bypass for the Beego framework. This vulnerability was reported in May, and after multiple follow-ups with no response, we have made the advisory public.
https://t.co/MtLDlSuzuX
I will be presenting my research into ORMs at Black Hat EU this year!
In my talk I showcase that an ORM could leak more data than what you joined for and methods on how to exploit a vulnerable use case, without exploiting an SQLi.
#BHEU@BlackHatEvents
https://t.co/oh6akHoRqB
Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher @hash_kitten has written up a blog post about a novel technique for SQL Injection in PDO’s prepared statements: https://t.co/oh7iVBc3t1
i will be dropping my fattest track at 7:30pm this friday
this song will straight up give you cholesterol
register to DownUnderCTF now!
https://t.co/VwPIepcg6A
Less than 2 days to go! The clock never stops! ⌛
Registrations are now open at:
https://t.co/VC71FNVWuB
Welcoming all skill levels! We can’t wait to show you what the team has cooked up this year! 🧑🍳
New writeup:
Early last month, @samwcyo, @sshell_, and I found a Django ORM injection in an online shooter game that let us steal cryptocurrency from the game's wallet.
Read the blog post here:
https://t.co/YjkIlEPX9q
Did you guess right? ONE month until DownUnderCTF 2025 kicks off and by now you should know what you’ll be doing this 18-20th July!
Join us! Share your interest here! https://t.co/mRG1BaAv6v
Congrats @toasterpwn winning the #Hexacon2024 CTF speed run yesterday. Great work by the @hexacon_fr team in organising it - it was great fun to watch!
If you want to try out an info leak challenge without SQLi check out my other challenge https://t.co/qO3kNoXZ2C
There are so many query logic bugs in the real world that are ripe for hacking.
It's a bummer I missed @BSidesCbr this year since I now live in Deutschland. But I was very happy to be part of the famous @cybearsCTF CTF. Thank you to everyone!
Btw, new ORM Leak payload for the beego web framework that bypasses allow listing prefixes https://t.co/ADAtb0oa8P
Cybears are getting ready to again awkwardly combine with the official BSides CBR theming! Join us on an epic quest to combine transformers, bears and LOTR into a fun CTF 🤣🤖🐻🏹⚔️ @BSidesCbr
@prisma@elttam A possible mitigation is switching operator options from string types to JS symbols, like what Sequelize has done (https://t.co/zHomeAl2FR). Then an attacker would not be able to control the operator by default. Downside is that this would introduce a breaking change.