New version of Gotator: v1.1. This version adds new flags (mindup and adv), improves results and reduces the number of duplicates.
https://github.com/Josue87/gotator
https://github.com/Josue87/gotator
GitHub
GitHub - Josue87/gotator: Gotator is a tool to generate DNS wordlists through permutations.
Gotator is a tool to generate DNS wordlists through permutations. - Josue87/gotator
👍1
How I found a bug in Apple within just in 5min
https://medium.com/pentesternepal/how-i-found-a-bug-in-apple-within-just-in-5min-d7357237d7a0
https://medium.com/pentesternepal/how-i-found-a-bug-in-apple-within-just-in-5min-d7357237d7a0
Medium
How I found a bug in Apple within just in 5min.
Summary: I discovered a Cross-site Scripting (XSS) vulnerability in one of the acquisition sites of apple which is Filemaker.com
Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth https://haxolot.com/posts/2021/moodle_pre_auth_shibboleth_rce_part1/
Haxolot
Pre-Auth RCE in Moodle Part I - PHP Object Injection in Shibboleth Module
It was found that the Shibboleth authentication module of Moodle suffers from a beautiful Remote Code Execution vulnerability from the unauthenticated perspective. This is widely used among universities to allow students from one university to authenticate…
Gaining Access To GCP Of Google Stadia
https://medium.com/@sebastien.kaul/gaining-access-to-gcp-of-google-stadia-500-bounty-22f76ecc8e60
https://medium.com/@sebastien.kaul/gaining-access-to-gcp-of-google-stadia-500-bounty-22f76ecc8e60
Medium
Gaining Access To GCP Of Google Stadia — 500$ Bounty
Learning machine authentication, finding a needle and gaining access to the Google Cloud project of Google Stadia.
Chaining Open Redirect with XSS to Account Takeover
https://radianid.medium.com/chaining-open-redirect-with-xss-to-account-takeover-36acf218a6d5
https://radianid.medium.com/chaining-open-redirect-with-xss-to-account-takeover-36acf218a6d5
Medium
Chaining Open Redirect with XSS to Account Takeover
Hello everyone, I hope you are well. In this article I will show you how I escalated XSS to Account Takeover. Since the target is private…
Facebook Vulnerability: Expose Group Member — $3000
https://medium.com/@muhammadsholikhin/facebook-vulnerability-expose-group-member-3000-cca809a53f6b
https://medium.com/@muhammadsholikhin/facebook-vulnerability-expose-group-member-3000-cca809a53f6b
Medium
Facebook Vulnerability: Expose Group Member — $3000
The issue is Insecure Direct Object with impact malicious user can expose or determine member on closed group. But the issue have limits…
How I Lost the SecurityTrails #ReconMaster Contest, and How You Can Win: Edge-Case Recon Ideas
https://securitytrails.com/blog/how-i-lost-the-securitytrails-reconmaster-contest
https://securitytrails.com/blog/how-i-lost-the-securitytrails-reconmaster-contest
Securitytrails
SecurityTrails | How I lost the SecurityTrails #ReconMaster contest, and how you can win: Edge-case recon ideas
'A while back, SecurityTrails announced that they would be running a contest dubbed 'Recon Master'. The aim of the game is to find hostnames that resolve to an IPv4 address that are not already found by SecurityTrails'
Forwarded from Android Security & Malware
XXE in Public Transport Ticketing Mobile APP
https://blog.niksthehacker.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1
https://blog.niksthehacker.com/xxe-in-public-transport-ticketing-mobile-app-81ae245c01a1
Medium
XXE in Public Transport Ticketing Mobile APP
This finding was an another private bug bounty program. The scope of the target was a ticketing android app (Prod). This app was a major…
Bug Bounty Stories #1: Tale of CSP bypass in an electron app!
https://securitygoat.medium.com/bug-bounty-stories-1-tale-of-csp-bypass-in-an-electron-app-f669f6ecefc9
https://securitygoat.medium.com/bug-bounty-stories-1-tale-of-csp-bypass-in-an-electron-app-f669f6ecefc9
Medium
Bug Bounty Stories #1: Tale of CSP bypass in an electron app!
Talking of a bug I found a long time back which led to the bypassing of CSP in an electron app :)
CSRF on /api/graphql allows executing mutations through GET requests
https://hackerone.com/reports/1122408
https://hackerone.com/reports/1122408
HackerOne
GitLab disclosed on HackerOne: CSRF on /api/graphql allows...
Mutations are `edit` or `create` queries used in Graphql. Gitlab prevents CSRF in this functionality by sending a POST request with a X-CSRF-Token header. The bug I found here was that, when we...
how to boost your popularity on okcupid using CSRF and a JSON type confusion
https://blog.azuki.vip/csrf/
https://blog.azuki.vip/csrf/
Webpack Exploder
Unpack the source code of React and other Webpacked Javascript apps! Check out Expanding the Attack Surface: React Native Android Applications to learn how to turbocharge your React hacking.
https://spaceraccoon.github.io/webpack-exploder/
Unpack the source code of React and other Webpacked Javascript apps! Check out Expanding the Attack Surface: React Native Android Applications to learn how to turbocharge your React hacking.
https://spaceraccoon.github.io/webpack-exploder/
spaceraccoon.github.io
Webpack Exploder
Unpack the source code of React and other Webpacked Javascript apps!