HackerOne's Hacktivity feed — a curated feed of publicly-disclosed reports — has seen its fair share of subdomain takeover reports. Since Detectify's fantastic series on subdomain takeovers, the bug b…
Commonly, malware will fingerprint the host it executes on, in an attempt to discover more about its environment and act accordingly. Part of this process is quite often dedicated to analyzing spec…
This was the P90_Rush_B challenge from Real World CTF Qualifiers - 2018, in which we participated as perfect blue This challenge was solved by @j0nathanj and @VoidMercy_pb. Unfortunately we did not ma…
1 августа 2018 года была опубликована статья "Тёмные паттерны Amazon", мало того, что переводная, так и кроме этого содержащая крайне мало фактических данных,...
downloaded are being scanned by the antivirus program
When IOfficeAntiVirus::Scan method is called by the programs (or internally via IAttachmentExecute) the system enumerates the Registry, collects info about all components implementing IOfficeAntiVirus, and stores them inside the following location
Google Open URL Redirection Vulnerability which does the Social Engineering part too.
on | | | | | | Twitter: @teh_h3ck Email: vag[d0t]mourikis[@]gmail.com Open URL Redirection definition, quoted by OWASP: "An open redirect is an application that takes a parameter and redirects a user …
Новая техника атак на основе Meltdown. Использование спекулятивных инструкций для детектирования виртуализации
Атака Meltdown открыла новый класс атак на процессоры, использующий архитектурные состояния для передачи информации. Но спекулятивное исполнение, которое было...
Take Advantage of Out-of-Scope Domains in Bug Bounty Programs • Abdullah Hu
Last year, I got an invitation from a private bug bounty program on HackerOne platform. I said let’s give it a try since I had some free time and here is the...
Внимание — это фривольный перевод заметки о том, как именно Jonathan Bouman нашёл публичный AWS S3, который использовался на одном из поддоменнов apple.com.
Vulnerability Discovery Against Apple Safari | Ret2 Systems Blog
Vulnerability discovery is the first stage of the exploit development lifecycle. The duration of this phase is open-ended because the search space, code qual...
Pentester's Windows NTFS Tricks Collection | SEC Consult
In this blog post René Freingruber (@ReneFreingruber) from the SEC Consult Vulnerability Lab shares different filesystem tricks which were collected over the