Forwarded from burpsuite (not official)
burpsuite_pro_v2.1.zip
279.3 MB
pass: 311138
java -jar burpsuite_pro_v2.1_BurpHelper.jar
java -jar burpsuite_pro_v2.1_BurpHelper.jar
Security analysis of <portal> element
https://research.securitum.com/security-analysis-of-portal-element/
https://research.securitum.com/security-analysis-of-portal-element/
research.securitum.com
Security analysis of <portal> element - research.securitum.com
Portal is a fairly new HTML element that is currently supported only in Chrome Canary behind the #enable-portals flag. Their main objective is to enable seamless transitions to the web by pre-rendering content in an iframe-like element that can be then “promoted”…
Graphql Abuse to Steal Anyone’s Address
https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417
https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
How i found a 1500$ worth Deserialization vulnerability
https://medium.com/@D0rkerDevil/how-i-found-a-1500-worth-deserialization-vulnerability-9ce753416e0a
https://medium.com/@D0rkerDevil/how-i-found-a-1500-worth-deserialization-vulnerability-9ce753416e0a
Medium
How i found a 1500$ worth Deserialization vulnerability
Note before you start.
Time-Based Blind SQL Injection In GraphQL
https://blog.usejournal.com/time-based-blind-sql-injection-in-graphql-39a25a1dfb3c
https://hackerone.com/reports/435066
https://blog.usejournal.com/time-based-blind-sql-injection-in-graphql-39a25a1dfb3c
https://hackerone.com/reports/435066
Medium
Time-Based Blind SQL Injection In GraphQL
I have heard a lot about GraphQL but never got time to understand due to time constraints. Recently, I got an application to pentest with…
Exploiting JSONP and Bypassing Referer
https://medium.com/bugbountywriteup/exploiting-jsonp-and-bypassing-referer-check-2d6e40dfa24
https://medium.com/bugbountywriteup/exploiting-jsonp-and-bypassing-referer-check-2d6e40dfa24
Medium
Exploiting JSONP and Bypassing Referer Check
Hi Folks, hope you are all fine, so this writeup is about exploiting JSONP to extract private data from API endpoints and bypassing the…
How I could have hacked your Uber account
https://appsecure.security/blog/how-i-could-have-hacked-your-uber-account
https://appsecure.security/blog/how-i-could-have-hacked-your-uber-account
www.appsecure.security
How I could have hacked your Uber account! - AppSecure Security
AppSecure is an offensive cybersecurity company, works with businesses across the world to protect their data, reputation, and brand.