Found 1481 bookmarks
Newest
XSS via unsanitized markdown output in pastebin.com and reddit.com
XSS via unsanitized markdown output in pastebin.com and reddit.com
We all love Markdown, right? It’s a fast and user-friendly way to beautify our documentation. Well, all that glitters is not gold, in this case not for system administrators.
·nhoya.github.io·
XSS via unsanitized markdown output in pastebin.com and reddit.com
CVE-2009-1437: RCE in CoolPlayer+ <= 2.19.6 (Windows 10 Pro)
CVE-2009-1437: RCE in CoolPlayer+ <= 2.19.6 (Windows 10 Pro)
While doing my preperation for the OSCE i found an exploit for the coolpalyer+ version 2.19.1 from 2009. I decided to check this vulnerability in the recent software version (2.19.6) on my Windows 10 …
·hansesecure.de·
CVE-2009-1437: RCE in CoolPlayer+ <= 2.19.6 (Windows 10 Pro)
iOS camera QR code URL parser bug
iOS camera QR code URL parser bug
I’ve learned recently that the iOS 11 camera app will now automatically scan QR codes and interpret them. This is pretty cool, until now you needed special apps to do that for you on iOS. When scannin…
·infosec.rm-it.de·
iOS camera QR code URL parser bug
SSD Advisory – Firefox Information Leak
SSD Advisory – Firefox Information Leak
Vulnerabilities Summary A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. T…
·blogs.securiteam.com·
SSD Advisory – Firefox Information Leak
Bypass an Adobe Flash Protection Mechanism
Bypass an Adobe Flash Protection Mechanism
The number of Flash Player exploits has recently declined, due to Adobe’s introduction of various measures to strengthen Flash’s security. Occasionally, however, an exploit still arises. On January 31…
·securingtomorrow.mcafee.com·
Bypass an Adobe Flash Protection Mechanism
Beyond XSS: Edge Side Include Injection - GoSecure
Beyond XSS: Edge Side Include Injection - GoSecure
new Web attack vector abusing the Edge Side Include (ESI) features common in caching services and product. We will explain the conditions required for exploitation along with 3 example…
·gosecure.net·
Beyond XSS: Edge Side Include Injection - GoSecure
cure53/XSSChallengeWiki
cure53/XSSChallengeWiki
Welcome to the XSS Challenge Wiki! Contribute to cure53/XSSChallengeWiki development by creating an account on GitHub.
·github.com·
cure53/XSSChallengeWiki
Detecting Hypervisor Presence on Windows 10
Detecting Hypervisor Presence on Windows 10
Detecting a hypervisor on Windows 10 is relatively simple, but due to the simplistic nature of the currently published detection vectors it’s likely that they are also relatively simple to spoof or…
·revers.engineering·
Detecting Hypervisor Presence on Windows 10
Как украсть деньги с бесконтактной карты и Apple Pay
Как украсть деньги с бесконтактной карты и Apple Pay
В статье разбираются популярные мифы и сценарии мошенничества с бесконтактными системами оплаты на примере настоящего POS-терминала, карт PayPass/payWave и...
·habr.com·
Как украсть деньги с бесконтактной карты и Apple Pay
Gamma Steganography
Gamma Steganography
Here’s a cool trick: try downloading this picture and looking at it in your file browser: If your computer is like mine, the output picture should look pretty different! Here’s what I see: So what hap…
·carlmastrangelo.com·
Gamma Steganography
Как я залил игру в Steam Store безо всякого одобрения со стороны Valve
Как я залил игру в Steam Store безо всякого одобрения со стороны Valve
Планировал ли я попасться? Конечно! Если вы посещали домашнюю страницу Steam в воскресенье вечером, вы могли заметить новую игру: «Смотрим на высыхание...
·habr.com·
Как я залил игру в Steam Store безо всякого одобрения со стороны Valve
Как я взломал Steam. Дважды
Как я взломал Steam. Дважды
Привет, Хабр! Сегодня я расcкажу за что же Valve заплатила наибольшие баунти за историю их программы по вознаграждению за уязвимости. Добро пожаловать под кат!...
·habr.com·
Как я взломал Steam. Дважды
Love letters from the red team: from e-mail to NTLM hashes with Microsoft Outlook
Love letters from the red team: from e-mail to NTLM hashes with Microsoft Outlook
Introduction A few months ago Will Dormann of CERT/CC published a blog post [1] describing a technique where an adversary could abuse Microsoft Outlook together with OLE objects, a feature of Microsoft Windows since its early days, to force the operating system to leak Net-NTLM hashes. Last year we
·blog.blazeinfosec.com·
Love letters from the red team: from e-mail to NTLM hashes with Microsoft Outlook
Brave Software disclosed on HackerOne: Local files reading from the...
Brave Software disclosed on HackerOne: Local files reading from the...
## Summary: `brave://` protocol was introduced as a replacement for `AsarProtocolHandler`(or something like that) in `brave/muon` after #375329. However, fix for #375329 introduced a new much...
·hackerone.com·
Brave Software disclosed on HackerOne: Local files reading from the...
Как работает Headless Chrome
Как работает Headless Chrome
Уже из названия понятно, что headless-браузер — это нечто без головы. В контексте фронтенда — это незаменимый инструмент разработчика, с помощью которого можно...
·habr.com·
Как работает Headless Chrome
Abusing just-in-time payment app in Chrome
Abusing just-in-time payment app in Chrome
While I was reading about Payment Handler API , I came across one sentence. Chrome also supports a non-standard feature we call just-in-ti...
·shhnjk.blogspot.com·
Abusing just-in-time payment app in Chrome