JohnHoder's profile picture.

John Hoder

@JohnHoder

Pinned

The body has to obey the will.


John Hoder reposted

🥷 Useful hotkeys to become @Burp_Suite ninja

ptswarm's tweet image. 🥷 Useful hotkeys to become @Burp_Suite ninja

John Hoder reposted

💛❤️💚💙 > This is oil chart and grey bar background is recessions > Notice how after every Oil spike theres a recession that follows.. > we’re about to get flogged .. jobs will be lost unfortunately

yourfriendSOMMI's tweet image. 💛❤️💚💙

> This is oil chart and grey bar background is recessions

> Notice how after every Oil spike theres a recession that follows..

> we’re about to get flogged .. jobs will be lost unfortunately

John Hoder reposted

In honor of current macro economic conditions I feel it would be criminal not to rewatch The Big Short🍿📽️


I was expecting that people would eventually start to switch from burp to something else since 2020. And here we are.

I think that I'm becoming a @zaproxy main now. Burp feels like it's over-engineered itself (for me, personal opinion) especially in spidering and scanning. Obviously, there are some extensions that I'll have to still use but other than those, I just like Zap better these days.



John Hoder reposted

I hope that even my worst critics remain on Twitter, because that is what free speech means


John Hoder reposted

I set myself the challenge of auto executing JavaScript without a click with the animate tag. You can now do this on Firefox and Chrome using the use element. portswigger.net/web-security/c…

PortSwiggerRes's tweet image. I set myself the challenge of auto executing JavaScript without a click with the animate tag. You can now do this on Firefox and Chrome using the use element.

portswigger.net/web-security/c…

John Hoder reposted

I have been able to capture #Flubots deployment code⚠️ 🔍This code is used on websites when a victim attempts to download the malicious APK Here is what I found ⤵️ 1/n

JCyberSec_'s tweet image. I have been able to capture #Flubots deployment code⚠️

🔍This code is used on websites when a victim attempts to download the malicious APK

Here is what I found ⤵️

1/n

John Hoder reposted

CVE-2021–35587 Oracle Access Manager Pre-Auth RCE Analysis. testbnull.medium.com/oracle-access-…

cyber_advising's tweet image. CVE-2021–35587 Oracle Access Manager Pre-Auth RCE Analysis.
testbnull.medium.com/oracle-access-…

John Hoder reposted

I hate `shutdown` when we had the long-time command `halt`


John Hoder reposted

I hate `systemctl poweroff` when we had the long-time command `shutdown` otherwise. It seemed like they changed the nomenclature intentionally just to be different.


John Hoder reposted
DhanSpeaks's tweet image.

John Hoder reposted

Take a deep dive into JSON Web Token implementation security with @intrigus_ and learn how they found a whole bunch of CVE with their latest bounty award winning ($4,500USD) #CodeQL query. This query is now included in the standard query set as well! github.co/3fPhQDw

GHSecurityLab's tweet image. Take a deep dive into JSON Web Token implementation security with @intrigus_ and learn how they found a whole bunch of CVE with their latest bounty award winning ($4,500USD) #CodeQL query. This query is now included in the standard query set as well! github.co/3fPhQDw

John Hoder reposted

Just discovered a weird but 100% working #WAF #Bypass - When RFI/LFI are blocked Don’t works. path=../../../etc/passwd file=config.xml Works. path=%00../../../etc/passwd file=%00config.xml This works successfully. Quite a new direction for WAF bypassing. #bugbounty #Infosec


John Hoder reposted

CVE-2021-3002 Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter. cve.mitre.org/cgi-bin/cvenam…


John Hoder reposted

As Microsoft have no intensions of ever paying me for all my submitted vulnerabilities I am forced to do this. Countdown starts today- then I will post them all public. Ms is just trying to get time to patch them then never pay me. I have for over 100.000$ in submissions. 14


John Hoder reposted

🤔

LiveOverflow's tweet image. 🤔

John Hoder reposted

Today is the day where @vodafoneNL will shut down their 3G network in favour of 2G and 4G. It's the first provider to do this in the Netherlands, so i'm interested to see the effect of it.


John Hoder reposted

Thanks Safari :D XSS via hash is back!!

kinugawamasato's tweet image. Thanks Safari :D XSS via hash is back!!

The legendary Masato Kinugawa almost solved an impossible lab but it requires X-XSS-Protection to be switched off and using Safari. Interestingly Safari doesn't URL encode the hash!



Loading...

Something went wrong.


Something went wrong.