Video write-up about the Real World CTF challenge "flaglab" that involved exploiting a GitLab 1day. Actually two CVEs were combined to achieve full remote code execution...
Как Amazon выбирает свои случайные предложения дня. И почему за ними так гонятся прода…
Amazon захватила 50% интернет-рынка в Америке. В прошлом году за пятинедельный период со Дня благодарения (22 ноября в США) 89% расходов клиентов крупнейших то...
#498964 Full access to internal Gitlab instances at redash.gitlab.com, dashboards.gitlab.com, promet…
**Summary:** Lack of proper ticket trick security leads to internal access on Gitlab instances. **I did not use support.gitlab.com instead just using [email protected] email was suffice....
DOMXSS on Embedded SDK via Shopify.API.setWindowLocation abusing cookie Stuffing
During H1-514, @filedescriptor reported an XSS issue in our Embedded App SDK that allowed for attacking legitimate apps through our platform, due to a missing protocol check on the...
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-clic…
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE Introduction and motivation How wireless device works and starts up Interaction between Wi-Fi S…
Persistence using Universal Windows Platform apps (APPX)
TL;DR Persistence can be achieved with Appx/UWP apps using the debugger options. This technique will not be visible by Autoruns. Two different approaches exists (registry keys). Listed below are the t…
Hunting mobile devices endpoints - the RF and the Hard way
When conducting intrusion tests, knowledge of endpoints and exchanged data is mandatory to test targeted applications, devices, and remote servers. If the target provides an Android, or iPhone applica…
XSS Vulnerabilities in Multiple iFrame Busters Affecting Top Tier Sites
For those unfamiliar with modern advertising tech, iFrame Busters are HTML files hosted on publisher sites which allow ad creatives to extend outside of their standard boundaries. These expandable cre…
In my previous blog post, I discussed different methods used to measure ads viewability. In the end of it, I've mentioned those methods could be spoofed by bad guys, and today I'll show you how. Origi…
Picasso: Lightweight Device Class Fingerprinting for Web Clients
In this work we present Picasso: a lightweight device class fingerprinting protocol that allows a server to verify the software and hardware stack of a mobile or desktop client.
Finding The Real Origin IPs Hiding Behind CloudFlare or Tor
Tor hidden services and reverse-proxy providers (e.g. CloudFlare) are useless if you are making simple mistakes. This is how you reveal the origin IPs.
## Introduction In Steam and other valve games (CSGO, Half-Life, TF2) there is a functionality to find game servers called the server browser. In order to retrieve the information about these...
IntroductionWhile DNS rebinding was first described nearly two decades ago, it has recently gained a second youth with the proliferation of insecure IoT devices and a series of highly publicized vulne…
Как я нашел пасхалку в защите Android и не получил работу в Google
Гугл любит пасхалки. Любит настолько, что найти их можно практически в каждом продукте компании. Традиция пасхалок в Android тянется с самых первых версий опера...