diffway545's profile picture.

diffway

@diffway545

diffway reposted

new blogpost time!! this one's a fun writeup on a vulnerability chain i found across multiple google services that earned me a $4133.70 bounty lots of fun css as usual! i had to recreate a bunch of drive/docs/gmail/youtube UIs c: have fun! lyra.horse/blog/2024/09/u…


diffway reposted

I just published Exploring the World of ESI Injection Feedbacks are appreciated , let me know if you liked it or not :) Special thanks to @nytr0gen_ link.medium.com/0WFFFk7n9vb


Start bug hunter Go go go


diffway reposted

Shodan HQ nmap plugin - passively scan targets:- This is an nmap nse script to query the Shodan API and passively get information about hosts. nmap --script shodan-hq.nse -sn -Pn -n <target> github.com/glennzw/shodan…


diffway reposted

💥 New article "Fuzzing for XSS via nested parsers condition" by our researcher @Psych0tr1a. This techniques allowed us to find a bunch of vulnerabilities in popular web products that no one had noticed before! swarm.ptsecurity.com/fuzzing-for-xs…


diffway reposted

Subdomain enum tool - Contributing to the community. Thanks to all those tool creators, I consolidated normalized and de-duplicated data. github.com/iamthefrogy/fr… #bugbounty #bughunting #appsec #applicationsecurity #cyber #cybersecurity #security #infosec #informationsecurity

iamthefrogy's tweet image. Subdomain enum tool - Contributing to the community. 

Thanks to all those tool creators, I consolidated normalized and de-duplicated data.

github.com/iamthefrogy/fr…

#bugbounty #bughunting #appsec #applicationsecurity #cyber #cybersecurity #security #infosec #informationsecurity

diffway reposted

Mail.ru disclosed a bug submitted by uddeshaya001: hackerone.com/reports/1287686 #hackerone #bugbounty

disclosedh1's tweet image. Mail.ru disclosed a bug submitted by uddeshaya001: hackerone.com/reports/1287686 #hackerone #bugbounty

diffway reposted

Finally, here is the blog for the prototype pollution research we did. "A tale of making internet pollution free" - Exploiting Client-Side Prototype Pollution in the wild pwn.af/research/pp

S1r1u5_'s tweet image. Finally, here is the blog for the prototype pollution research we did.

&quot;A tale of making internet pollution free&quot;
 - Exploiting Client-Side Prototype Pollution in the wild

pwn.af/research/pp

diffway reposted

Looking for motivation to do some cloud security research? ☁️🔒 Let us remind you of the $313,337 we'll be giving out in total prizes this year to the top 6 bug reports in GCP. More details: security.googleblog.com/2021/03/announ…


diffway reposted

CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy (Reported by @albinowax ) demo: github.com/CHYbeta/OddPro… article: 1、portswigger.net/research/http2 2、articles.zsxq.com/id_zztmlo4l3hb…

chybeta's tweet image. CVE-2021-33193 Request splitting via HTTP/2 method injection and mod_proxy (Reported by @albinowax )
 
demo: github.com/CHYbeta/OddPro…

article: 
1、portswigger.net/research/http2
2、articles.zsxq.com/id_zztmlo4l3hb…

diffway reposted

Mattermost disclosed a bug submitted by @AkashHamal0x01: hackerone.com/reports/1114347 - Bounty: $150 #hackerone #bugbounty

disclosedh1's tweet image. Mattermost disclosed a bug submitted by @AkashHamal0x01: hackerone.com/reports/1114347 - Bounty: $150 #hackerone #bugbounty

diffway reposted

Write-up on how a Facebook bug could have exposed your email/phone number to your friends. Quick and easy.😉 Bounty: $18250 #BugBounty iamsaugat.medium.com/a-facebook-bug…


diffway reposted

Topcoder disclosed a bug submitted by @{}: hackerone.com/reports/978823 #hackerone #bugbounty

disclosedh1's tweet image. Topcoder disclosed a bug submitted by @{}: hackerone.com/reports/978823 #hackerone #bugbounty

United States Trends

Loading...

Something went wrong.


Something went wrong.