I discovered a Server-Side Request Forgery (SSRF) vulnerability in InvoiceNinja, which allowed unauthorized access to local files on the server. For a more detailed explanation, you can refer to the following link:
https://t.co/K7TN1KDu7a
#CVE-2024-53353 #bugbounty#pentest
A few months ago, we successfully utilized a Blind Cross-Site Scripting (XSS) vulnerability that was impacting two major companies.
In this blog post, we explained in detail on how we were able to achieve this.
#bugbounty#pentesting
https://t.co/1lcXwR83E3
New blog: Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust
I teased this a bit during my Windows Hello talks, now found some time to write about this interesting technique. Also contains defenses and detection opportunities.
https://t.co/KSPVRm5iGo
In this blog post published by @preterallc, I share a review of the Burp Suite Certified Practitioner exam that I recently passed.
#bugbounty#burpsuitecertified
https://t.co/ir5R3qC7iI
I'm thrilled to announce that I've recently become a Burp Suite Certified Practitioner!
I highly recommend PortSwigger Academy's labs to anyone looking to improve their skills in this area.
#burpsuitecertified
Read how recently our team managed to compromise a #biometric device by chaining a couple of #vulnerabilities, from default #credentials to abusing a vulnerable web service used by the biometric device.
@arbennsh details all this into a blog post:
https://t.co/HLFw04su7w