Olga Barinova
@_lely___
Manager, Product Security @Okta
You might like
The comprehensive list of today's emerging threats, nOtWASP bottom 10: vulnerabilities that make you cry by @albinowax, @artsploit and @garethheyes portswigger.net/research/notwa…
New attacks on OAuth: SSRF by design and Session Poisoning by @artsploit portswigger.net/research/hidde…
The top 10 web hacking techniques of 2020, by @albinowax with help from @filedescriptor, @irsdl, @Agarri_FR and the entire community portswigger.net/research/top-1…
Power up the Burp Suite and get stuck into our latest Web Security Academy topic! We've designed a whole new set of labs on OAuth Authentication for your password-avoiding pleasure. portswigger.net/web-security/o… #websecurityacademy #burpsuite #OAuth2
Can you spot a critical vulnerability in this innocent code? Learn about Spring View Manipulation in our latest article github.com/veracode-resea… #java @springframework
Jolokia enhances JMX remoting with unique features like pre-auth RCE 🤔
Mail.ru disclosed a bug submitted by johndoe1492: hackerone.com/reports/703910 - Bounty: $2,000 #hackerone #bugbounty
We have confirmed the successful demonstration from @artsploit used a previously reported bug. This counts as a partial win, but does earn him 12.5 Master of Pwn points. #P2OMiami #S4x20
Up next and making his #Pwn2Own debut, Michael Stepankin (@artsploit) of Veracode will be targeting a remote code execution with continuation against the Inductive Automation Ignition in the Control Server category. #P2OMiami #S4x20
Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :) spaceraccoon.dev/remote-code-ex…
I'm excited to share my post about discovering & exploiting multiple critical vulnerabilities in Cisco's DCNM. Busting Cisco's Beans :: Hardcoding Your Way to Hell srcincite.io/blog/2020/01/1… PoC exploit code: srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-…
Our guy, @SecurityMB, had a presentation at OWASP Poland Day about exploiting prototype pollution to RCE on the example of Kibana, by abusing environmental variables in node. The slides are here: slides.com/securitymb/pro… We will also release a writeup soon so stay in touch!
Here are my slides from XSS magic tricks slideshare.net/GarethHeyes/xs…
Apache Solr Injection whitepaper is now available at github.com/artsploit/solr… Thanks everyone who attended my #defcon talk!
Short story about blind HQL Injection (MySQL case) #hqlinjection #hibernate #spiderlabs trustwave.com/en-us/resource…
Apache Solr research is completed and I'm happy to present some ways to RCE in this innocent looking search engine. See you @ #defcon27 @defcon defcon.org/html/defcon-27… …
In our latest blog post we show you various ways how to attack RMI based JMX services. We also release our fork of sJET, which is called MJET (obviously). mogwailabs.de/blog/2019/04/a…
Expression Injection in Qlik Products (CVE-2019-11628). The fresh advisory has been published just now. trustwave.com/en-us/resource…
Blog post about attacking Java RMI services, a extension to the talk from Hans-Martin Münch at this years Bsides Munich mogwailabs.de/blog/2019/03/a…. You can also find the slides/material on our GitHub account #BSidesMUC19
heh :D
What a neat 'Function.prototype.toString()' implementation in modern javascript! If you can control the key of a class object to be returned, 'constructor'.toString() returns the whole class Source code.
United States Trends
- 1. McBride N/A
- 2. taemin N/A
- 3. #OrmBlossominShanghaiEvent N/A
- 4. Chase N/A
- 5. ORMKORN BA BLOSSOMIN N/A
- 6. #DragRace N/A
- 7. Gibbs N/A
- 8. #OPLive N/A
- 9. #FreenFanSignInTIANJIN N/A
- 10. SAROCHA AT TIANJIN EVENT N/A
- 11. Gobert N/A
- 12. The Rip N/A
- 13. #JustinStrong N/A
- 14. Jaylon Tyson N/A
- 15. Sengun N/A
- 16. Mandy N/A
- 17. Julius Randle N/A
- 18. Rockets N/A
- 19. Michael Cohen N/A
- 20. Dylan Cardwell N/A
You might like
-
Tanner
@itscachemoney -
Josip Franjković
@JosipFranjkovic -
@[email protected]
@SecurityMB -
Allyson O'Malley
@ally_o_malley -
Mikhail Klyuchnikov
@m1ke_n1 -
Ben Hayak
@BenHayak -
Omar "Beched" Ganiev
@theBeched -
Timur Yunusov
@a66ot -
Raz0r
@theRaz0r -
Dmitry Serebryannikov
@dsrbr -
harisec
@har1sec -
Mikhail Firstov
@cyberpunkych
Something went wrong.
Something went wrong.