If you see android:exported="true" in AndroidManifest.xml in Android pentests, you should definitely try the intent injection method, this may give you ssrf, exfiltration sensitive data, rce. 🥰🌹🥳
#BugBounty#bugbountytips
🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!
I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐 #infosec #xz
🎉 Version v9.7.6 of Nuclei Templates is here!
⚡️ Super powered with:
🧬 49 new Templates
🥇 12 first-time contributions
🛡️ 22 new CVEs added
https://t.co/PtBFIsMMLW
https://t.co/1lgtOSXLS2
this tool lets you extract text from an audio recording of keyboard strokes, right now, for free
i am not making this shit up, you can potentially steal a password from an audio recording in an office
NUCLEI CHEATSHEET
A small addition for those who have read my article "Using Nuclei for OSINT. A 5-minute basic guide":
https://t.co/fvXS7PTux6
You only need to know 10 commands (flags) from this cheatsheet to start using #Nuclei.
🍪💣 Cookie Bomb 💣🍪
URL that causes the cookie length to exceed request header limits for all requests until the cookie expires.
1. Find a Cookie set by a parameter
2. Inject as many commas as you can into the parameter until you DoS that user
#bugbountytips#infosec
GitHub - MattKeeley/Spoofy: Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records. https://t.co/E4y04yF7z1