Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...
15.01.2025 15:24 โ ๐ 24 ๐ 8 ๐ฌ 0 ๐ 7@abdilahrf.bsky.social
CTF / Bugbounty / Web Guy
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...
15.01.2025 15:24 โ ๐ 24 ๐ 8 ๐ฌ 0 ๐ 7Use golden goose until its not golden ๐คฃ๐
14.01.2025 03:16 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0TIL that the recent Ivanti ImportXML vulnerability is a second-order XXE, where the payload must be enclosed in the CDATA section of a SOAP request ๐ฆพ
15.12.2024 12:00 โ ๐ 14 ๐ 4 ๐ฌ 0 ๐ 1Slow race condition but 11 chars! terjanq.me/solutions/jo... Let me know if that works for you. With that, time to stop ๐
13.12.2024 20:34 โ ๐ 5 ๐ 1 ๐ฌ 0 ๐ 0In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! ๐ Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Donโt miss it:
youtu.be/JERBqoTllaE?...
Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE.
Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...