#CyberPanel (n)day pre-auth root RCE drop š
I also intended to note down my mental process while auditing code since the bug is relatively easy, definitely recommended for upcomers
Left a challenge at the end if you want to find your own n-day bug :)
dreyand.rs/code/review/20ā¦
Just wrote a ~2.5 page blog post on Client Side Path Traversal, covering what CSPT is, why it can be so impactful, some advanced exploitation and WAF bypass techniques, and a bug which I found in a live hacking event (redacted ofc)
matanber.com/blog/cspt-leveā¦
Super Easy Finding!
add /camunda/app/welcome/default/#!/login to your wordlist! :) & remember the default creds!
demo:demo
#bugbountytips #bugbountytip #bugbounty
18K Followers 222 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
8K Followers 381 FollowingI love GraphQL | Hackerone Ambassador š²š¦ | Tweets are my own | Riichi #Mahjong Player Master Tier | see https://t.co/hqRuoXEQH3 before DM :)
8 Followers 462 FollowingFiguring out how to protect networks while fueled by coffee. ā | Management Information Technology student & InfoSec enthusiast.
8 Followers 196 Following"ATTACK OR DEFEND?? You have to decide, which side you are."
I am OSCP certified, Security Researcher, Bug Bounty Hunter, Freelancer.
52K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
412 Followers 1K FollowingManager I, Security Research @datadoghq | he/him | ex https://t.co/o1EIMjEmIk, https://t.co/r3eI34P95R | my website: https://t.co/Zcg7COPgTk
Opinions are mine!
11K Followers 299 FollowingTruth Seeker.
Catholic.
Hacker.
Prompter.
Techno-Ethicist.
Chasing my Apotheosis.
Views are correct.
Truth is at the intersection of Athens & Jerusalem
33K Followers 920 FollowingFounder of @DarkEntryAMS. Vulnerabilities Hunter since 2013. ex Sr. Manager at Visa Inc, HackerOne, Deloitte, QCERT and EGCERT. Tweets are my own.
16K Followers 0 FollowingTips and tricks for Burp Suite Pro
Managed by @Agarri_FR | Not affiliated with @Portswigger
More free resources at https://t.co/MWqXmV66lr
43K Followers 897 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
27K Followers 630 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks