I created a nmap compatible list of all vulnerable software from National Vulnerability Database.
A modified version of it will be shipped with the next release of Silver.
Dump: https://t.co/0CE5R6kxRy
Dataset: https://t.co/zFMxykPm65
Blogged: It's important to 'stick to basics' - Secure your important assets by adding an additional layer of authentication (2FA or SAML based login). It was a great experience working with @Samsung security team. #bugbounty#infosecurity
https://t.co/0nLvdK73KI
There's no way to organize posts by topic on Medium, so here goes:
SSRF posts:
Intro to SSRF - https://t.co/USHmWFlSI8
Exploiting SSRF - https://t.co/HwST3ifZjm
Bypass SSRF protection - https://t.co/2WFG9Frrw9
SSRF statistics - https://t.co/OIwQ1ZFxFw
CVE-2019-8451 Unauthorized SSRF via REST API /plugins/servlet/gadgets/makeRequest
use @ to bypass the whitelisting !
https://t.co/aEJ2v7MACf
👇 reading resources @orange_8361
https://t.co/9DBKCpRcQl
I'm publishing some 🔥 research today, a major design flaw in Windows that's existed for almost *two decades*. I wrote a blog post on the story of the discovery all the way through to exploitation.
https://t.co/1DFW2VGQRb
Here are the slides from our talk at @defcon - "Owning the clout through SSRF and PDF generators". We'll probably write 3 blog posts on a few bug bounty examples soon! Also a big thank you to @daeken for being my partner in crime through this research. https://t.co/zWxWTkCXJ6
Ran into an API subdomain with an empty response?
You may get lucky and fetch the full API spec by hitting the following endpoints:
/swagger-ui.html
/swagger/swagger-ui.html
/api/swagger-ui.html
/v1.x/swagger-ui.html
/swagger/index.html
...
#bugbountytips#bugbounty#hackerone