Retour à la réalité après encore une très bonne cuvée 2025 pour @_leHACK_ en compagnie de @Gromak123_Sec et freesec! Merci à toute l’organisation pour le boulot monstre comme chaque année c’est toujours un kiff d’être là ! Merci @hackerzvoice et on oublie pas:
Hack the planet🍻
Here are the slides from my @TumpiConIT talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU)
https://t.co/ncwizyHAXk
@AREtoiles Quel est le nom de l'œuvre littéraire qui a été écrite par l'écrivain argentin Jorge Luis Borges et qui explore le concept d'infini à travers une bibliothèque contenant tous les livres possibles, et quel est le titre de ce récit ?
In the past few months, I've been making a subdomains database containing 1.6 billion subdomains scrapped from multiple public (and private) sources.
This database is now public and FREE and can be queried on the following website.
https://t.co/C2cXn3sUOD
Enjoy!
A new open-source tool from @BitK_ reveals how popular browsers parse HTML – simplifying the hunt for mutation XSS and opening up new horizons in security research 🔬 Read about this valuable addition to your 'Hacker's Toolbox' in our latest blog post 👇
https://t.co/rQyRdhseP5
uro v1.0.1 is here 🎉
- 80 times faster (real)
- fixed that unicode error
- fixed high RAM usage while reading from stdin
- harsher /{int}/ type filtering
https://t.co/qlLQBfU6Kz
Oneliner + A collection of special paths linked to major web frameworks and infrastructure projects, known juicy APIs, misconfigurations.. etc.
dirsearch -l 200HTTP --full-url -F -w leaky-paths.txt
https://t.co/faOL6pswPY
#bugbounty#bugbountytips#bugbountytip#hacking
Chrome now supports onscrollend! This works with any tag. Now you can bypass that WAF on Chrome and Firefox. Check out our XSS cheat sheet for a PoC:
https://t.co/5niLsBsyvp
Did you know you can hide your payloads in phone numbers? ☎️😱
RFC3966 specifies parameters for valid phone numbers that can contain characters. @securinti discovered that popular libraries are vulnerable and that it can lead to XSS and even ATO!🔥
#BugBountyTips#NahamCon2022EU
APKLeaks is a very efficient tool for extracting links and secrets from mobile .apk applications quickly. Thanks for the #BugBountyTip, @_superhero1! #BugBountyTips
RSA destroyed 😱
Well-known cryptographer Schnorr posted a preprint that, in his words, «destroys the RSA cryptosystem» !
https://t.co/r434XwR1Cf
There was initially some confusion if this paper was really from him, but this is now confirmed: https://t.co/4VszxZ9qcg .
Finding postMessage vulnerabilities has never been easier, take a look at our first open-source tool from @enso_security which provides GUI and Cross Origin traffic inspector in ease.
https://t.co/ctvy0EG3Ix
Looking forward to see your findings using posta!
#bugbountytips
We have updated the github repository with all the tricks from the past year.
Github: https://t.co/UussQhab9p
Telegram: https://t.co/bPXBYZT5P7
HackerScrolls team: @barracud4_ and @igc_iv
Feel free to suggest any security topic in replies
Good luck & have fun in New Year 2021!