@intigriti@Burp_Suite Finally got it! I got stuck for 2 days in the last step. What a relief! Thanks again for this challenges. I'll try to make a writeup once it's finished.
3️⃣0️⃣0️⃣K #HTB MEMBERS Reached 🥳
Thank you for choosing #HackTheBox as your #Hacking Training Platform! 💚 We are celebrating it by giving away 5 annual VIP subscriptions! For the #Twitter family, like and RT this post for a chance to WIN 1 YEAR VIP 😎
#CyberSecurity#HTBCommunity
Thinking about getting stoned and starting the blog back up tonight with the first post a basic intro to bug hunting, and some of my routine for hunting bugs. If this can get 100 retweets then I'll start on it, otherwise xbox sounds like just as much fun lol. #bugbounty
I’ve basic ‘id=1’ SQLi in a WP environment. Stackpath WAF is filtering “union select” and similars. Is there anything I can do to bypass it? Rt appreciated. Thanks!
200K HTB Subscribed Members! 🥳
Thank you all for your support and dedication all these years.
It has been an amazing journey and we can’t wait for the next adventures to come.
As a thank you to the community, RT and three lucky members will win annual VIP.
Good Luck!
I learnt today that IP addresses can be shortened by dropping the zeroes.
Examples:
http://1.0.0.1 → http://1.1
http://192.168.0.1 → http://192.168.1
This bypasses WAF filters for SSRF, open-redirect, etc where any IP as input gets blacklisted.
#infosec#bugbounty#bugbountytip
Hopefully you all updated your Macs to the latest macOS version, because as promised in my talk at #OBTS, KeySteal is now available on Github: https://t.co/62HPyKnnHx
Please, only use this exploit for educational purposes. Don’t be evil!
After my @objective_see#OBTS talk I'm finally releasing the full research writeup for my root privilege escalation on macOS, which is now fixed. It's here: https://t.co/5qUXEWIaNJ