CDN cache bugs hide in normalization gaps.
Test same authenticated endpoint through variants:
/account
/account/
/account%2f
/account;%2fstyle.css
/account..;/style.css
Watch: Cache-Status, Age, Set-Cookie, Vary, Authorization handling. One 200 with user data + public cache key is reportable fast.
#BugBounty #AppSec #Pentesting #WebSecurity #CyberSecurity
most SSRF bugs fetch data from internal services and return it to the attacker. impactful but usually bounded.
this one used SSRF to take over an entire Google Cloud project.
Sreeram found a client-side SSRF, where the browser is the one making the request, not the server. a JavaScript execution context on a Google domain was making fetch requests that could be redirected.
the target: the GCP metadata endpoint.
https://t.co/gOf4yqP4Vy.internal/computeMetadata/v1/instance/service-accounts/default/token
this endpoint, accessible from any GCP instance, returns the OAuth token for the instance's service account.
from the browser running JavaScript on a Google domain, hitting this endpoint returns the token for the underlying cloud instance's service account.
with that token, he could authenticate to Google Cloud APIs as the service account, modify project configurations, access cloud resources, and project takeover.
client-side SSRF is underrated because people assume SSRF requires server-side execution. if the JavaScript on a page makes fetch() calls and you can influence the URL, the browser itself becomes the SSRF proxy. and browsers on cloud infrastructure have access to metadata endpoints.
List of all essential things that you need to make your workflow 10x faster and smarter in claude.
Four most necessary files:
1) Claude.md - it defines how Claude should behave while working on your project.
It’s like a system prompt but stored as a file.
for ex:How to respond (concise, detailed, structured, etc.)
Preferred format (bullets, code-first, explanations)
Tone (professional, simple, technical)
2) Project.md- This file defines the overall project scope and rules.
What it contains:
>Project overview
>Goals and objectives
>Tech stack
>Coding standards
>Folder structure
>Constraints / guidelines
3) Context.md - This file provides dynamic, task-specific context.
What it contains:
>Current task or feature
>Relevant files / modules
>Recent changes
>Dependencies
>Notes or assumptions
4) Feedback.md- it is used to store feedback about Claude’s outputs and continuously improve future responses. so that claude don't make the same mistakes again
Skills and plugins
>pr-review-toolkit
>learning-output-style, explanatory-output-style
>feature-dev
>code-simplifier
>code-review
>claude-md-management
>claude-code-setup
>plugin-dev skill-creator
>security-guidance
>playwright
>context7
>commit-commands
Advanced skills
>caveman
>ui-ux-pro-max-skill
>superpowers
>claude-code-terminal-title
>claude-hud
>frontend-design
>webapp-testing
Essential MCPs
>Google Drive
>Gmail
>Huggingface
>Github
Registration is open for our April Flash CTF at https://t.co/8L5FKSDL8M!
The top winner and selected raffle participants can choose from prizes sponsored by our partners, @Antisy_Training, Simply Cyber Academy, and @TCMSecurity.
Practice at https://t.co/wr6rR7go11
🚨 FREE CERT ALERT: The Junior Vibe Pentester (JVP) certification is currently $0 (was $50).
🛡️ Use code: Free50
🔗 Get it here: https://t.co/hPrNVJzKqW
Go get those labs!
#InfoSec#CyberSecurity#BugBounty
Exam Voucher Giveaway
Prize: CISSP
How to enter:
- Follow me
- Retweet this post
Picking a winner in 7 days.
Good luck!
(Please make sure your DMs are open)
I recently discovered a super cool website inspection tool called Web-Check. It has a strong hacker vibe.
It lets you inspect almost everything about a website: IP details, SSL, DNS records, cookies, domain info, crawler rules, server location, redirect history, open ports, traceroute, DNSSEC, site performance, associated hostnames, and more.
https://t.co/A5B83COLK7
Just wrapped up an OSINT CTF challenge based on a real Europol Most Wanted case involving the LOCKERGOGA ransomware operations (2018–2020)
A solid exercise in applying lawful OSINT research to connect public clues without speculation.
@OSINTindustries#OSINTIndustriesCTF#CTF
GIVEAWAY TIMEEEEE - BIGGGG BUNDLE
======================
Who wants to join my 900 hacker's toolkit for FREE?
The ONLY bundle on the internet like this - with direct coaching through discord and a wealth of information in the form of all my courses - all my live lessons - and ALL my certs? [INCLUDING ALL FUTURE CONTENT]
https://t.co/yRAFtWkRJd
Yes, I am talking about this hacker's toolkit - the only bundle on the internet for just 90 euro's with the most amount of info and that NEVER stops growing!
What you gotta do?
- Like the post
- Tag your favourite content creator (curious to see who you will pick :D ) - NOT ME
- Repost this post
You have 72 hours :-) Let the games begin