Introducingggggg... 🥁
Generate thousands of URL path combos in seconds, perfect for generating brute force wordlists!
mkpath! This tool is similar to mksub, but it works for URL path combinations instead of subdomains.
https://t.co/HTmcA16jbS
1/ #Linux#Forensics: pssst... I will now reveal my favorite interview question for candidates who want to work in our IR team ;) "In the process list, I see a (running) binary, but the binary is no longer present on disc. How can I restore the original binary? (screenshot 👇)"
🧵Another hacker story thread! 🧵
== The Medical Alert Hack ==
Not too long ago I put a whole city on high alert during a security assessment. A tale of caution. 💀
Read along to learn my approach & mistakes!
🚨Retweet, follow, & like for more hacker stories! 🚨
1/x
👇🏼
Recent P1 bug I found:
1. App allowed admin to create GitHub profile with access token.
2. User is only allowed to call to external url based on admin config.
3. App uses graphql
4. Found endpoint to generate a user jwt
5. Used query to dump graphql data.
I am honestly impressed by the new reports @wallarm have been able to give #GoTestWaf in the new version!
Visually, I can see everything i need in 1 quick overview and I can zoom in ...
And apparently I need to up my security 👹👹
https://t.co/LnR1D8voRL
Expand your attack surface by grabbing SSL certificates from ip addresses, match these with your Bug Bounty targets.
I'd recommend running this technique on cloud providers such as AWS/Azure/GCP ranges
using https://t.co/uvvFVrKTXC
cero [CIDR] (cero 0.0.0.0/0)
#bugbountytips
The comprehensive list of today's emerging threats, nOtWASP bottom 10: vulnerabilities that make you cry by @albinowax, @artsploit and @garethheyes
https://t.co/ZrXcqHC2bM
The Assetnote security research team discovered a full-read SSRF vulnerability in Jamf Pro (post-authentication) a few months ago. https://t.co/mOaKcJHVUe (CVE-2021-39303 & CVE-2021-40809). Tracing sinks to sources is always a valid strategy.