🚨 HTTP/1.1 doit mourir 🚨
Pas de 0-day magique : juste des écarts d’interprétation entre front & back → attaques CL.0 / 0.CL, cache poisoning (même sur Cloudflare), response queue poisoning…
🎥 Vidéo : youtu.be/cImKS9xfpIg
🔥 Giveaway Time 🔥
I’m giving away a seat in the Endless Bundle (all courses, all labs, certs, community, future updates).
How to enter:
- RT/Share this post
- Tag a hacker friend
- That’s it
Winner picked tomorrow. 🐀 I will retweet their comment this time so it's more clear…
🚀 Big Announcement! 🚀
After 8+ years of working on PayloadsAllTheThings, I’m excited to release it as an ebook on Leanpub! 📖✨
To celebrate, I’m gifting 5 free copies to random retweeters! 🔥
👉 Retweet for a chance to win
Thank you all for your incredible support! 🙌…
Let’s not say we’ve reported this behavior to Kong back in 2023 and they replied that it was a « problem within burp » instead of a vuln in their tool 🤷♂️ I know few people that got mistreated by this Kong « security » team for this bug and others, cc @TheLaluka@askilow
Let’s not say we’ve reported this behavior to Kong back in 2023 and they replied that it was a « problem within burp » instead of a vuln in their tool 🤷♂️ I know few people that got mistreated by this Kong « security » team for this bug and others, cc @TheLaluka@askilow https://t.co/jKgshApBKY
With @FlatNetworkOrg we took part in the @1ns0mn1h4ck finals and we ended up in second place. The Insotransfer challenge was about an RCE on a FastAPI readonly docker instance, enjoy the read :)
worty.fr/post/writeups/…
I developed a Burp vulnerability scanning plug-in based on #DeepSeek model, which can detect injection vulnerabilities and XSS vulnerabilities at present
#bugbounty#bugbountytips
I welcome your questions in the Github Issues section
github.com/momika233/Deep…
Hello la commu !
Vous l'avez vu on a communiqué autant qu'on a pu sur la nouvelle formation 0x41 avec toute la dream-team rassemblée pour le projet.
Ca avance bien (merci à vous ! 💕), et les pré-qualifications commencent aujourd'hui !
Est-ce que ca veut dire que c'est trop…
Hello la commu !
Vous l'avez vu on a communiqué autant qu'on a pu sur la nouvelle formation 0x41 avec toute la dream-team rassemblée pour le projet.
Ca avance bien (merci à vous ! 💕), et les pré-qualifications commencent aujourd'hui !
Est-ce que ca veut dire que c'est trop…
Is anyone familiar with code which executes when the machine is locked?
You could invoke WTSRegisterSessionNotification and wait until the WM_WTSSESSION_CHANGE message is received with WTS_SESSION_LOCK to begin payload execution.
tl;dr malware only runs when machine locked
Hey hunters,
I'm sharing a little tool I created to gather all the #YWH program info you have and sort it by relevance in one place.
Choose the best program & Let's go for bounties 💰!
Link : github.com/jdouliez/ywh_p…@yeswehack#sharingiscaring bugbountyTips #😂
The current set of AI tools reminds me of the early days of the internet, with its related and/or competing technologies, like Usenet, Telnet, WAIS, FTP, Gopher and WWW/HTTP. Nobody yet knew which would succeed or fail. It was a time of curiosity, excitement -- and nervousness…
The current set of AI tools reminds me of the early days of the internet, with its related and/or competing technologies, like Usenet, Telnet, WAIS, FTP, Gopher and WWW/HTTP. Nobody yet knew which would succeed or fail. It was a time of curiosity, excitement -- and nervousness… https://t.co/YpCqx9r3Q8
New papers added:
- 2024-11-21 - New AMSI Bypss Technique Modifying CLRDLL in Memory
- 2024-11-22 - How To Use MSSQL CLR Assembly To Bypass EDR
- 2008-08-06 - Branchless Equivalents of Simple Functions
- 2024-06-28 - An unexpected journey into Microsoft Defender's signature…
Administrative update:
tl;dr bradley is out, i'm back. reorganizing papers. were collecting cats. no more goofing around.
0. Bradley is out-of-office. He was supposed to man-the-ship. He has experienced a family medical emergency. I am now steering the ship again.
1. Currently…
2K Followers 3K FollowingTailored cybersecurity upskilling platform for all levels, catering to beginners and pros | Best way to boost your #cybersecurity skills
26K Followers 2 FollowingOffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.
16K Followers 3K Following#SCOP d'experts du #LogicielLibre
Confiez nous la performance de vos applications (hébergement, infogérance, #devops, #SRE, sécurité, efficacité énergétique)
2K Followers 259 FollowingPentester, Web specialized 🪲 Top 30 YesWeHack https://t.co/bJ2s5TWqYf
Check my website if you're bored https://t.co/tdzCTEUbuO :)
10K Followers 155 Following🐴Pwnie Award Winning & Nation State funded psyop featuring 6 AI Anime Waifus and a Pup™ singing about APTs, Grifters, & Snake Oil in InfoSec
🖤🩷💚💙💜🤍
155K Followers 0 FollowingThe free and flexible app for your private thoughts. For help and deeper discussions, join our community: https://t.co/QsDArfFkkv
950 Followers 96 FollowingCybersecurity meets metal. Shirts for fictional bands named after malware and threat actors. Literal malwear. DM for international orders. Requests are welcome.
20K Followers 480 FollowingRoot Me allows everyone to test and improve their knowledge in computer security and hacking. Legal. Free. Realistic. Discord: https://t.co/G6y1wDrdOn
187K Followers 105 FollowingWe're sharing/showcasing best of @github projects/repos. Follow to stay in loop. Promoting Open-Source Contributions. UNOFFICIAL, but followed by github