HExHTTP v2.5 is out ! 🥳
- Many fixes for bugs & FP (a huge reduction !)
- HHMP (Host Header Manipulation Poisoning) & CFP (Change Format Page) CPDoS module
- Generates an interactive HTML report from scan results with -o option (export json/csv in HTML)
& more in CHANGELOG.md,
If you find it useful, consider supporting the project - even a small contribution helps a lot !
https://t.co/uyw0Z2lC77
Pushed a new update to https://t.co/9CqANckHK0 -- it now scans for the RCE payload via reflection. Use the --waf-bypass flag to bypass WAFs, works well for Cloudflare/AWS. Other WAFs might need tinkering with the payload, depending on whether they don't have a max context limit.
Last Week, With @NaimGlj we were rewarded for our effective collaboration.
In just a few hours of hunting, we found a few bugs in @yeswehack including two critical ones, for a total of $7,000.
Aside from the reward, it was my first collaboration and it was a great experience
Guillaume Chouquet, fondateur et directeur de l'ESNA, viré de sa propre école par l'@Formation_bzh !!!
Je suis consterné et en colère.
C'est affligeant de prendre une telle décision quand on sait tout ce que le bonhomme a fait pour l'école et les alternants !
What if your Everest was to take your client/server web security skills to the next level (and boost your Root-Me points in the process)? ⛰️💻
5 new challenges are now available in the Web-Client and Web-Server categories
👉 https://t.co/yBGycCTMmk
Thanks to the authors: @YoOx15, @Rolix_cy, @kevin_mizu and #jrjgjk! 🙏
#RootMe
Just got a reward for a critical vulnerability submitted on @yeswehack -- Use of Hard-coded Credentials (CWE-798). https://t.co/RN1N26Dr8z #YesWeRHackers
Goal for 2024 is complete: to find a critical vulnerability and achieve the max reward. ✅
I can't wait for the BlackHole 😁
For Christmas 2023, Root-Me has decided to thank its favorite hackers! 🥳
Two prize packages including XXL mouse pads, mugs, stickers, flags, and pins are up for grabs ! 🎁
To participate, it's as simple as :
- Follow @rootme_org
- RT 🔃 this post
- Being verified on the official Discord Root-Me
The two winners will be randomly selected on December 28th at 6 p.m. !
Good luck to everyone and happy holidays ! 🎅🤶