msd0s7's profile picture. I help companies secure their web applications - Cybersecurity strategy, pentesting and advisory | OSCP - CRTP - CARTP
#cybersecurity #pentesting #webapp #api

Andrei Agape

@msd0s7

I help companies secure their web applications - Cybersecurity strategy, pentesting and advisory | OSCP - CRTP - CARTP #cybersecurity #pentesting #webapp #api

𝐑𝐞𝐥𝐞𝐚𝐬𝐢𝐧𝐠 "𝐒𝐎𝐀𝐏𝐈 - 𝐒𝐜𝐚𝐧𝐧𝐞𝐫 𝐨𝐟 𝐎𝐩𝐞𝐧𝐀𝐏𝐈" 𝐝𝐨𝐜𝐮𝐦𝐞𝐧𝐭𝐚𝐭𝐢𝐨𝐧𝐬 👇 After my OWASP presentation from last year, many people asked me when/if the tool is public because they'd love to give it a try Well, now it is! 😄 github.com/andrei8055/SOA…

github.com

GitHub - andrei8055/SOAPI: SOAPI - The OpenAPI Documentation Scanner

SOAPI - The OpenAPI Documentation Scanner . Contribute to andrei8055/SOAPI development by creating an account on GitHub.


Level up your offsec skills with the Weekly Pentest Tips & Tricks course 👇 sqrsec.com/tips-and-tricks


𝐓𝐢𝐫𝐞𝐝 𝐨𝐟 𝐭𝐡𝐞 𝐬𝐚𝐦𝐞 𝐨𝐥𝐝 𝐟𝐮𝐳𝐳𝐢𝐧𝐠 𝐰𝐨𝐫𝐝𝐥𝐢𝐬𝐭𝐬? 👇 Download my custom-made collection of API wordlists which I scraped from 120,000+ public documentations -> API ports, paths, parameters, objects, headers and many more: sqrsec.com/api-fuzzing-li…


Andrei Agape أعاد

CVE-2024-22272 VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud … cve.org/CVERecord?id=C…


SVGs images (unlike other image types) don't rely on unique pixels But they use 'vector' data What many applications and developers fail to understand is that SVG files are just XML documents with graphical tags. This is usually abused to inject XXE, XSS and SSRF payloads

msd0s7's tweet image. SVGs images (unlike other image types) don't rely on unique pixels

But they use 'vector' data

What many applications and developers fail to understand is that SVG files are just XML documents with graphical tags.

This is usually abused to inject XXE, XSS and SSRF payloads

GraphQL DoS Payload 👇 This payload abuses the option to concatenate multiple queries into one single request. When the number of batched requests were increased, an exponential increase in response time was also observed, ultimately exhausting the server. #graphql #pentest

msd0s7's tweet image. GraphQL DoS Payload 👇

This payload abuses the option to concatenate multiple queries into one single request.

When the number of batched requests were increased, an exponential increase in response time was also observed, ultimately exhausting the server.

#graphql  #pentest

Loading...

Something went wrong.


Something went wrong.