@I_Am_Jakoby Look at the image @I_Am_Jakoby, this wasn’t a leak.. pops doesn’t know how autofill works 😆. There’s at best, a handful of numbers left in that scroll bar…
@techspence Your missing a whole lot here @techspence
Deny access to this computer from the network
Deny log on as a batch job
Deny log on as a service
What about all the other T0 builtin groups? EA,Account Operators,administrators, dnsadmins,dcom, cert publishers etc.
@wadgamaraldeen I’m saying you didn’t try hard enough. Is there another gadget to chain it with at this moment? Maybe, maybe not. That’s what’s notes and JavaScript monitoring is for. Come back to it later.
Reporting an open redirect on any bbp today will likely yield similar results.
@wadgamaraldeen But it did have zero impact to the company. You’re presenting a hypothetical. The quicker you understand that the quicker you will find real bugs.
You should have kept that open redirect in your notes. Combined with an xss on another page would be an ato.