Join me on the @offby1security channel for a stream with the amazing @albinowax on August 15th @ 11AM PT on "Novel HTTP/1 Request Smuggling/Desync Attacks!" Be sure to turn on alerts for the channel on YouTube...
https://t.co/Zcdi1l9fHj
Google CTF will start in less than 48h from now. Make sure not to miss the great challenges we've prepared this year!! Can't describe how exicted I am for it 😶
The upcoming "HTTP/1 must die" @WebSecAcademy lab is no longer impossible! This is good news because I'm planning to attempt to live-stream solving it...
This week’s Disclosed. #BugBounty
Beta invite for Hai, the AI security agent for hackers. RCE on Netflix. New tools for XSS, subdomain monitoring, and HTTP smuggling. Plus: SSTI, IDN homographs, and more.
Highlights below 🧵
🌀 𝗦𝗺𝘂𝗴𝗴𝗹𝗲𝗙𝘂𝘇𝘇 - A modular HTTP request smuggling fuzzer built for deep desync exploration.
👉 https://t.co/YuS8gOcjNz
Perfect for testing reverse proxies, finding obscure smuggling vectors, and pushing fuzzing boundaries.
#CyberSecurity#RedTeam#BugBounty
Wrote a Burp Suite Pro extension that uses AI-powered features to replace values in HTTP requests.
Useful for guessing data formats based on parameter or header names. For example, for requests from Swagger / OpenAPI or those generated by my tool BFScan.
https://t.co/BXwXWr7OM6
Excited to share our latest blog post, where we dive into attacking CEFSharp-based thick clients and introduce CefEnum, our new tool for enumerating and analyzing these applications. Check it out to learn more about securing .NET thick clients: https://t.co/gt6B23KjT8
I have launched a new web CTF. Amazon gift-card for first to solve, and swag draw amongst successful submissions. site: https://t.co/OsRiYf0rN5 Code: https://t.co/2m7shenxf4
@troyhunt@haveibeenpwned Can replicate on Samsung Galaxy A32 + Firefox Focus. But then again this model struggles with most sites. It seems more fluid once you reach the listings on the page.