Forwarded from The Bug Bounty Hunter
Unrestricted file upload vulnerability
https://medium.com/@519udhaya/unrestricted-file-upload-vulnerability-bba4491a08da
https://medium.com/@519udhaya/unrestricted-file-upload-vulnerability-bba4491a08da
Medium
Unrestricted file upload vulnerability
Hi guys whatsup! This is Udhay an security researcher . Here im presenting my research on unrestricted file upload vulnerablities.
Forwarded from The Bug Bounty Hunter
[1/n] Practical walkthrough on how I found an XSS injection and used @PortSwigger @garethheyes XSS cheatsheet to bypass a WAF on a @Hacker0x01 program recently:
Via: https://twitter.com/spaceraccoonsec/status/1177877957844459520
Via: https://twitter.com/spaceraccoonsec/status/1177877957844459520
Forwarded from The Bug Bounty Hunter
HackBar V2
[No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
https://addons.mozilla.org/en-US/firefox/addon/hackbar-free/
[No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
https://addons.mozilla.org/en-US/firefox/addon/hackbar-free/
addons.mozilla.org
HackBar V2 – Get this Extension for 🦊 Firefox (en-US)
Download HackBar V2 for Firefox. [No License, FOREVER FREE] A HackBar for new firefox (Firefox Quantum). This addon is written in webextension and alternatives to the XUL version of original Hackbar.
You can ask request here: https://github.com/Hack-Free/HackBar
You can ask request here: https://github.com/Hack-Free/HackBar
Forwarded from The Bug Bounty Hunter
🚨NEW CHALLENGE: Can you find the XSS vulnerability? 🕵️♂️
🎁 Win a Burp Pro license and private invites at
Via: https://twitter.com/intigriti/status/1178641697779191808
🎁 Win a Burp Pro license and private invites at
Via: https://twitter.com/intigriti/status/1178641697779191808
Twitter
🚨NEW CHALLENGE: Can you find the XSS vulnerability? 🕵️
🎁 Win a Burp Pro license and private invites at
👉https://t.co/ujjUzeuRt2! 👈
#HackWithIntigriti
🎁 Win a Burp Pro license and private invites at
👉https://t.co/ujjUzeuRt2! 👈
#HackWithIntigriti
Forwarded from The Bug Bounty Hunter
Steal ALL collateral during liquidation by exploiting lack of validation in
flip.kick
https://hackerone.com/reports/684092HackerOne
BlockDev Sp. Z o.o disclosed on HackerOne: Steal ALL collateral...
## Summary:
The `flip` contract allows for the MCD system to auction collateral in exchange for DAI.
A lack of validation in the method `flip.kick` allows an attacker to create an auction with a...
The `flip` contract allows for the MCD system to auction collateral in exchange for DAI.
A lack of validation in the method `flip.kick` allows an attacker to create an auction with a...
Forwarded from The Bug Bounty Hunter
How a double-free bug in WhatsApp turns to RCE
https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/
Home
How a double-free bug in WhatsApp turns to RCE
In this blog post, I’m going to share about a double-free vulnerability that I discovered in WhatsApp for Android, and how I turned it into an RCE. I informed this to Facebook. Facebook acknowledged and patched it officially in WhatsApp version 2.19.244.…