Is there a way to find out if application is running PHP version < 8?
- phpinfo is NOT available
- Errors are suppressed
#php#bugbounty#hackers#hunters#cve
The easiest way to find a max-impact desync vulnerability in 2024:
1. Create a novel desync technique
2. Add it to a tool like HTTP Request Smuggler
3. Scan a bunch of systems and see what sticks.
The only tricky step is #1 and there's a new tool to help with this 1/2
We found two 0-day vulnerabilities in @ubuntu kernel and it all started by reading descriptions of old CVEs 📖
Thread about the discovery of #GameOverlay 🧵👇🏼
Universal MXSS. Works in all browsers and is likely to bypass lots of filters because title is both an SVG and HTML tag. Briefly checked DOM Purify and it looked okay.
What happens when you type a URL into a browser? The method to download the high-resolution PDF is available at the end.
Let’s look at the process step by step.
Step 1: The user enters a URL (bytebytego .com) into the browser and hits Enter. The first thing we need to do is to…
🚨 BREAKING: History written with just 9 lines of code!
We've discovered #PyLoose, the FIRST documented Python-based fileless attack targeting cloud workloads.
See the power of 9 lines of Python code below 👇🏽
1 Followers 128 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/vyvxFc2UAf
642 Followers 4K FollowingIT security vendor with HQ in UAE and offices in Lithuania and Singapore. We bring evolution to the #PKI, #IAM, #PrivillegedAccessManagement, #AccessManagement
16K Followers 4K FollowingConsciously Remembering God 🤲🏾🎶 Kids Teacher 👨🏼🏫 Music Artist & Podcast Host 😭🎙️ Proud Muslim 🕌 The CRG App Open Beta Live 🚨🚨🚨
175K Followers 162 FollowingCall group https://t.co/iaokVvPUO0 . Fast Trading Bot 👉 https://t.co/DyzEBKdHXq (Code rix for 10% off fees).Tweets NFA. Some PnL = luck or info. DYOR @solbix_bot
10K Followers 0 FollowingAssetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
817 Followers 577 FollowingAn Ex-SWE who is currently learning everything about security via CTF.
Security @osec_io | Member of @Water_Paddler & Blue Water | DEF CON CTF 31 & 32 Finalist
1.3M Followers 23K Following#SpacesHost | Truth Slayer | ↗️ I follow all Subscribers • Let's end the establishment media • ʟɪꜱᴛᴇɴ ᴡɪᴛʜ ᴄᴜʀɪᴏꜱɪᴛʏ. ꜱᴘᴇᴀᴋ ᴡɪᴛʜ ʜᴏɴᴇꜱᴛʏ. ᴀᴄᴛ ᴡɪᴛʜ ɪɴᴛᴇɢʀɪᴛʏ.
188K Followers 972 FollowingProud Zionist/Jew, Global Speaker (50+ cities), Tech Columnist, Advisor (Google, Microsoft, Oracle), Dad x5. Banned from Australia. We will dance again! 🇮🇱💪
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
No recent Favorites. New Favorites will appear here.