Bug Bounty Stories #1: Tale of CSP bypass in an electron app!
https://securitygoat.medium.com/bug-bounty-stories-1-tale-of-csp-bypass-in-an-electron-app-f669f6ecefc9
https://securitygoat.medium.com/bug-bounty-stories-1-tale-of-csp-bypass-in-an-electron-app-f669f6ecefc9
Medium
Bug Bounty Stories #1: Tale of CSP bypass in an electron app!
Talking of a bug I found a long time back which led to the bypassing of CSP in an electron app :)
CSRF on /api/graphql allows executing mutations through GET requests
https://hackerone.com/reports/1122408
https://hackerone.com/reports/1122408
HackerOne
GitLab disclosed on HackerOne: CSRF on /api/graphql allows...
Mutations are `edit` or `create` queries used in Graphql. Gitlab prevents CSRF in this functionality by sending a POST request with a X-CSRF-Token header. The bug I found here was that, when we...
how to boost your popularity on okcupid using CSRF and a JSON type confusion
https://blog.azuki.vip/csrf/
https://blog.azuki.vip/csrf/
Webpack Exploder
Unpack the source code of React and other Webpacked Javascript apps! Check out Expanding the Attack Surface: React Native Android Applications to learn how to turbocharge your React hacking.
https://spaceraccoon.github.io/webpack-exploder/
Unpack the source code of React and other Webpacked Javascript apps! Check out Expanding the Attack Surface: React Native Android Applications to learn how to turbocharge your React hacking.
https://spaceraccoon.github.io/webpack-exploder/
spaceraccoon.github.io
Webpack Exploder
Unpack the source code of React and other Webpacked Javascript apps!
Security researcher finds dangerous bug in Chromium, nabs $15,000 bounty
https://portswigger.net/daily-swig/security-researcher-finds-dangerous-bug-in-chromium-nabs-15-000-bounty
https://portswigger.net/daily-swig/security-researcher-finds-dangerous-bug-in-chromium-nabs-15-000-bounty
The Daily Swig | Cybersecurity news and views
Security researcher finds dangerous bug in Chromium, nabs $15,000 bounty
Site isolation security break uncovered
$50k bug bounty on Shopify explained (GitHub access token leaked via electron application)
https://youtu.be/xOoWHKOphK0
https://youtu.be/xOoWHKOphK0
YouTube
$50k bug bounty on Shopify explained (GitHub access token leaked via electron application)
In this video we walk through how a security researcher named Augusto Zanellato was able to discover a GitHub Personal Access Token (PAT) that had read/write access to private Shopify repositories, and earned them a $50,000USD bounty!
You can read the report…
You can read the report…
👍1
Forwarded from Android Security & Malware
Facebook Messenger for Android indirect thread deletion vulnerability
https://servicenger.com/blog/mobile/android/facebook-messenger-for-android-indirect-thread-deletion/
https://servicenger.com/blog/mobile/android/facebook-messenger-for-android-indirect-thread-deletion/
Internal Gitlab Ticket Disclosure via External Slack Channels
https://hackerone.com/reports/1273292
https://hackerone.com/reports/1273292
Easiest Critical Bug triaged on HackerOne https://medium.com/@sahildari/easiest-critical-bug-triaged-on-hackerone-f84bb4c9266
Medium
Easiest Critical Bug triaged on HackerOne
Greetings awesome Hackers. I’m Sahil Dari and this is my first blog on my first easiest Critical report triaged on HackerOne. I don’t need…
Intigriti’s PHP challenge breakdown https://securitygoat.medium.com/intigritis-php-challenge-breakdown-178f5d003986
Built from the ground up in Rust, Caido aims to help security professionals and enthusiasts audit web applications with efficiency and ease
https://caido.io/
https://caido.io/
Caido
Caido aims to help security professionals and enthusiasts audit web applications with efficiency and ease.
What is BOLA? 3-digit bounty from Topcoder ($$$)
https://infosecwriteups.com/what-is-bola-3-digit-bounty-from-topcoder-a25e7fae0d64
https://infosecwriteups.com/what-is-bola-3-digit-bounty-from-topcoder-a25e7fae0d64
Medium
What is BOLA? 3-digit bounty from Topcoder ($$$)
This write-up will be about Broken Object Level Authorization (BOLA), which is #1 topic of API Security 101 (OWASP).
Insecure Bundler configuration fetching internal Gems (okra) from Rubygems.org
https://hackerone.com/reports/1104874
https://hackerone.com/reports/1104874
HackerOne
Basecamp disclosed on HackerOne: Insecure Bundler configuration...
I found an internal gem (Ruby library) in use by Basecamp that was not registered on Rubygems (the public Ruby package repository). I registered a gem of my own under the name that would call back...