New blog post on a recent collab with @UsmanMansha420 where I bypassed Akamai WAF to get RCE on a Java application with Spring EL injection. Spent some time writing about the process of constructing the custom payload. Hope you enjoy! https://t.co/hsuRmM3fx6
I just published a blog post for the people that want to get into bug bounties. I hope it helps people that are thinking about doing bug bounties, but haven't started yet. It explains what to expect and how to deal with common problems / situations: https://t.co/V9CKTpJzPT
I earned $2,500 for my submission on @bugcrowd https://t.co/QpdfQ5CfqM #ItTakesACrowd
SQL to RCE
Thanks for the post below that gave me the idea.
https://t.co/odmQiZFkb1
@Mdhsan19@0x1int The lowest impact is Reflected XSS which can be done with the following payload:
<domain>/docpicker/internal_proxy/http/brutelogic.com.br/poc.svg