#websec wyniki wyszukiwania

Discovered a very interesting path based SQLi yesterday. Injected: /‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/ → No delay /page/‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/test.test triggered delay. Same payload, different results. Here's why👇 1/4 #BugBounty #SQLi #WebSec

nav1n0x's tweet image. Discovered a very interesting path based SQLi yesterday. Injected: /‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/ → No delay 
/page/‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/test.test triggered delay. Same payload, different results. Here's why👇 1/4 #BugBounty #SQLi #WebSec

Ché pasate por una birra bien fría a #LABARRADELAEKO, antes de que se acaben! 🍻 #EKO2025 #Websec #HappyHacking


Turn a file write vulnerability in a Node.js application into remote code execution sonarsource.com/blog/why-code-… Credits Stefan Schiller #infosec #websec

0xor0ne's tweet image. Turn a file write vulnerability in a Node.js application into remote code execution

sonarsource.com/blog/why-code-…

Credits Stefan Schiller

#infosec #websec
0xor0ne's tweet image. Turn a file write vulnerability in a Node.js application into remote code execution

sonarsource.com/blog/why-code-…

Credits Stefan Schiller

#infosec #websec

Help me get to 900🥹🙏🏾 #websec #pentesterlab #cybersecurity

c1ph3rbnuk's tweet image. Help me get to 900🥹🙏🏾
#websec #pentesterlab #cybersecurity

How many likes to get a #pentesterlab pro membership?🥹



This year’s swag is lit 🔥 🔥 Huge thanks to @msftsecresponse !! #bugbounty #websec #infosec

Fatnass1F1ras's tweet image. This year’s swag is lit 🔥 🔥

Huge thanks to @msftsecresponse !!

#bugbounty #websec #infosec

Always fun to get a DDoS attack on a Friday afternoon. 😑 Kudos to @kinsta and their APM + IP tools. It was relatively easy to track down and mitigate the attack. #websec

brianleejackson's tweet image. Always fun to get a DDoS attack on a Friday afternoon. 😑

Kudos to @kinsta and their APM + IP tools. It was relatively easy to track down and mitigate the attack.

#websec

Pásele primo, estamos regalando #HackingFuel a.k.a café en nuestro stand 🤠 #Websec #Pwnterrey

_websec's tweet image. Pásele primo, estamos regalando #HackingFuel a.k.a café en nuestro stand 🤠 #Websec #Pwnterrey

Logical Bugs are often invisible to scanners They live in the assumptions devs make Want to find them? Think like the app shouldn’t work Here are 6 strategies to uncover logic bugs (with examples): #bugbounty #websec #cybersecurity

ReconOne_bk's tweet image. Logical Bugs are often invisible to scanners
They live in the assumptions devs make
Want to find them? Think like the app shouldn’t work

Here are 6 strategies to uncover logic bugs (with examples):
#bugbounty #websec  #cybersecurity

We are thrilled to announce that @_websec is once again joining forces with BSides Vancouver Island as a Silver Tier Sponsor! 🎉 A huge thank you to Websec for their continued support and for fostering a space where professionals can connect, learn, and grow. #Websec #BSidesVI

BSidesVI's tweet image. We are thrilled to announce that @_websec is once again joining forces with BSides Vancouver Island as a Silver Tier Sponsor! 🎉 A huge thank you to Websec for their continued support and for fostering a space where professionals can connect, learn, and grow. #Websec #BSidesVI

Good times and consecutive bounties achieved with @intigriti define professionalism #bugbountytip #CyberSec #websec

Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec
Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec
Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec

Last night I had the pleasure of speaking at the first-ever #owasp Victoria meetup! This is me, with chapter leaders Christophe David and Roberto Salago!! @wehackpurple and #WebSec proudly sponsored. @OWASPVictoria @LightOS

shehackspurple's tweet image. Last night I had the pleasure of speaking at the first-ever #owasp Victoria meetup! This is me, with chapter leaders Christophe David and Roberto Salago!! @wehackpurple and #WebSec proudly sponsored. @OWASPVictoria @LightOS

Ep 1 of my PortSwigger sprint: Found a quick win with classic SQLi! Bypassed a product filter to retrieve hidden data. Lesson: Never concatenate user input directly into SQL queries! #WebSec #SQLinjection #AppSec

T3chFalcon's tweet image. Ep 1 of my PortSwigger sprint: Found a quick win with classic SQLi! Bypassed a product filter to retrieve hidden data.

Lesson: Never concatenate user input directly into SQL queries! #WebSec #SQLinjection #AppSec

#SSRF Payloads for LFR/LFD file:/etc/passwd%3F/ file:/etc%252Fpasswd/ file:/etc%252Fpasswd%3F/ file:///etc/%3F/../passwd file:${br}/et${u}c%252Fpas${te}swd%3F/ file:$(br)/et$(u)c%252Fpas$(te)swd%3F/ SSRF POLYGLOT file:///etc/passwd?/../passwd #WebSec rodoassis.medium.com/on-ssrf-server…


Venha se aventurar em mais uma edição do CTF da websecbrasil!!! @YuriRDev Discord.gg/websec #CyberSecurity #cibersegurança #websec #dev #ctf #capturetheflag

Evoluwillsec's tweet image. Venha se aventurar em mais uma edição do CTF da websecbrasil!!!
@YuriRDev
Discord.gg/websec #CyberSecurity #cibersegurança #websec #dev #ctf #capturetheflag

Doing more API labs today🤖#websec #apis #api

s3curetheweb's tweet image. Doing more API labs today🤖#websec #apis #api

Uncle @theXSSrat on top. This will help many hackers to grow and learn about the cybersecurity. #BugBounty #websec #Pentesting #xssrat #xss

darshanhackz's tweet image. Uncle @theXSSrat on top.
This will help many hackers to grow and learn about the cybersecurity. 
#BugBounty #websec #Pentesting #xssrat #xss

Catch our next session with @_smile_hacker_ on "Request Smuggling and Its Exploitation"! Dive into how this web vulnerability works and how to defend against it. RSVP: null.community/events/1025-ah… #CyberSecurity #WebSec @null0x00 #nullahm

NullAhm's tweet image. Catch our next session with @_smile_hacker_  on "Request Smuggling and Its Exploitation"! Dive into how this web vulnerability works and how to defend against it.

RSVP: null.community/events/1025-ah…

#CyberSecurity #WebSec @null0x00 #nullahm

Help me get to 900🥹🙏🏾 #websec #pentesterlab #cybersecurity

c1ph3rbnuk's tweet image. Help me get to 900🥹🙏🏾
#websec #pentesterlab #cybersecurity

How many likes to get a #pentesterlab pro membership?🥹



Bug Hunters Alert! Using httpx? Be aware it strips the = from empty query params (?q= ➡️ ?q). This shifts the payload from Empty String to Null. For ASP.NET/Rails, this is a False Negative risk. 🚩 Don't miss bugs! bit.ly/4pDzonR #bugbounty #infosec #websec

zeroc00i's tweet image. Bug Hunters Alert! Using httpx? Be aware it strips the = from empty query params (?q= ➡️ ?q).

This shifts the payload from Empty String to Null. For ASP.NET/Rails, this is a False Negative risk. 🚩 Don't miss bugs!

bit.ly/4pDzonR

#bugbounty #infosec #websec

Just exploited a JWT authentication bypass at 1 AM Stay-logged-in cookie? More like "stay-pwned" cookie 💀 This is why JWT security matters. Let me break down how I bypassed auth in 4 simple steps 🧵👇 #JWT #CyberSecurity #WebSec #BugBounty

Cyber_matri_x's tweet image. Just exploited a JWT authentication bypass at 1 AM
Stay-logged-in cookie? More like "stay-pwned" cookie 💀
This is why JWT security matters. Let me break down how I bypassed auth in 4 simple steps 🧵👇
#JWT #CyberSecurity #WebSec #BugBounty

Today I practiced error-based blind SQL injection (Oracle) using CASE logic and controlled division-by-zero errors. #WebSec #portswigger #SQL

enochkanabia's tweet image. Today I practiced error-based blind SQL injection (Oracle) using CASE logic and controlled division-by-zero errors.
#WebSec #portswigger #SQL
enochkanabia's tweet image. Today I practiced error-based blind SQL injection (Oracle) using CASE logic and controlled division-by-zero errors.
#WebSec #portswigger #SQL
enochkanabia's tweet image. Today I practiced error-based blind SQL injection (Oracle) using CASE logic and controlled division-by-zero errors.
#WebSec #portswigger #SQL

New write-up: Command Injection — From basics to defense. Covering visible vs blind injection, reverse shells, bypass tricks, and concrete hardening steps. Read: medium.com/@oe7836196/com… Ethical reminder: test only with permission. #infosec #pentest #websec


Day 71 🔎 Dug into content spoofing, hyperlink & HTML injection. Practiced spotting manipulated content and responsibly disclosing findings. “Find the flaw, fix the future.” #WebSec #EthicalHacking

PKennygold's tweet image. Day 71 🔎
Dug into content spoofing, hyperlink & HTML injection. Practiced spotting manipulated content and responsibly disclosing findings.

“Find the flaw, fix the future.”

 #WebSec #EthicalHacking

✅ Finished the NoSQL injection (data extraction) lab! Learned how query structure and operator misuse can expose sensitive data — and why schema validation, parameterization, and input sanitization are must-haves. #CyberSecurity #WebSec #NoSQL @CyberMindSpace

rikki59845's tweet image. ✅ Finished the NoSQL injection (data extraction) lab!
Learned how query structure and operator misuse can expose sensitive data — and why schema validation, parameterization, and input sanitization are must-haves.
#CyberSecurity #WebSec #NoSQL @CyberMindSpace

Dove into a lab on REST URL parameter pollution — used request inspection (high level) to see how duplicate/ambiguous params altered behavior. Reinforced why servers must normalize and validate URL input. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace

rikki59845's tweet image. Dove into a lab on REST URL parameter pollution — used request inspection (high level) to see how duplicate/ambiguous params altered behavior. Reinforced why servers must normalize and validate URL input. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace

🧩🎉 Explored mass assignment — reminder that unchecked model binding can let attackers set unexpected fields. #AppSec #WebSec @CyberMindSpace

rikki59845's tweet image. 🧩🎉 Explored mass assignment — reminder that unchecked model binding can let attackers set unexpected fields. #AppSec #WebSec @CyberMindSpace

Dove into a lab on query-string parameter pollution — used safe request inspection (high level) to see how duplicate params altered behavior. Reinforced why servers must normalize and validate query inputs. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace

rikki59845's tweet image. Dove into a lab on query-string parameter pollution — used safe request inspection (high level) to see how duplicate params altered behavior. Reinforced why servers must normalize and validate query inputs. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace

🎉 Explored Web shell upload via race condition! Eye-opening reminder that upload logic + race conditions = dangerous combos. #WebSec #AppSec @CyberMindSpace @anand114bug @RohitVishw54326

rikki59845's tweet image. 🎉 Explored Web shell upload via race condition! Eye-opening reminder that upload logic + race conditions = dangerous combos. #WebSec #AppSec @CyberMindSpace @anand114bug @RohitVishw54326

🎉 Completed Web cache poisoning → DOM vuln (strict cacheability)! Great lesson on how even strict caching rules can be abused to reach client-side sinks. #WebSec #CachePoisoning #XSS @CyberMindSpace @anand114bug @RohitVishw54326

rikki59845's tweet image. 🎉 Completed Web cache poisoning → DOM vuln (strict cacheability)! Great lesson on how even strict caching rules can be abused to reach client-side sinks. #WebSec #CachePoisoning #XSS @CyberMindSpace @anand114bug @RohitVishw54326

✅ Completed Cryptography Basics! Learned about symmetric encryption (AES), public key cryptography (RSA), and the importance of hashing (SHA). Key management is crucial in real-world security — always use strong, unique keys! 🔐 #Crypto #WebSec #InfoSec @CyberMindSpace

rikki59845's tweet image. ✅ Completed Cryptography Basics! Learned about symmetric encryption (AES), public key cryptography (RSA), and the importance of hashing (SHA). Key management is crucial in real-world security — always use strong, unique keys! 🔐 #Crypto #WebSec #InfoSec @CyberMindSpace

🎉 Explored URL Normalization! Great deep dive into how small differences in URLs (encoding, case, slashes) can change app logic or caching behavior. #WebSec #AppSec #InfoSec @CyberMindSpace @RohitVishw54326 @anand114bug

rikki59845's tweet image. 🎉 Explored URL Normalization!
Great deep dive into how small differences in URLs (encoding, case, slashes) can change app logic or caching behavior. #WebSec #AppSec #InfoSec @CyberMindSpace @RohitVishw54326 @anand114bug

Wrapped up web cache poisoning (fat GET request) — used Burp Suite + curl to observe how large/complex GETs affected cached responses (high level). Reinforced CDN & backend cache hygiene. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace @RohitVishw54326 @anand114bug

rikki59845's tweet image. Wrapped up web cache poisoning (fat GET request) — used Burp Suite + curl to observe how large/complex GETs affected cached responses (high level). Reinforced CDN & backend cache hygiene. 🔍🛠️ #BurpSuite #WebSec @CyberMindSpace @RohitVishw54326 @anand114bug

🎉 Completed Web Parameter Cloaking lab! Eye-opening on how hidden/alternate params can change app behavior and bypass naive filters. #WebSec #AppSec @CyberMindSpace @anand114bug @RohitVishw54326

rikki59845's tweet image. 🎉 Completed Web Parameter Cloaking lab! Eye-opening on how hidden/alternate params can change app behavior and bypass naive filters. #WebSec #AppSec @CyberMindSpace @anand114bug @RohitVishw54326

🎉 Completed Web cache poisoning (unkeyed query parameter)! Eye-opening lab on how query params excluded from cache keys can poison responses. #WebSec #CachePoisoningWeb @CyberMindSpace @anand114bug @RohitVishw54326

rikki59845's tweet image. 🎉 Completed Web cache poisoning (unkeyed query parameter)! Eye-opening lab on how query params excluded from cache keys can poison responses. #WebSec #CachePoisoningWeb @CyberMindSpace @anand114bug @RohitVishw54326

🎉 Completed Targeted web cache poisoning (unknown header)! Eye-opening lab on how unexpected headers can change cache behavior. #WebSec #CachePoisoning #CDN @CyberMindSpace @anand114 @RohitVishw54326


Discovered a very interesting path based SQLi yesterday. Injected: /‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/ → No delay /page/‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/test.test triggered delay. Same payload, different results. Here's why👇 1/4 #BugBounty #SQLi #WebSec

nav1n0x's tweet image. Discovered a very interesting path based SQLi yesterday. Injected: /‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/ → No delay 
/page/‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/test.test triggered delay. Same payload, different results. Here's why👇 1/4 #BugBounty #SQLi #WebSec

Turn a file write vulnerability in a Node.js application into remote code execution sonarsource.com/blog/why-code-… Credits Stefan Schiller #infosec #websec

0xor0ne's tweet image. Turn a file write vulnerability in a Node.js application into remote code execution

sonarsource.com/blog/why-code-…

Credits Stefan Schiller

#infosec #websec
0xor0ne's tweet image. Turn a file write vulnerability in a Node.js application into remote code execution

sonarsource.com/blog/why-code-…

Credits Stefan Schiller

#infosec #websec

I am excited to share that I got the Bug Killer Badge on @hackthebox_eu for finding a bug in production. This is amazing 😻. some goals coming along fine this year. #hackthebox #bugbounty #websec #tech #infosec

beingsheerazali's tweet image. I am excited to share that I got the Bug Killer Badge on @hackthebox_eu for finding a bug in production.
This is amazing 😻. some goals coming along fine this year. 
#hackthebox #bugbounty #websec #tech #infosec

Blind SQL Injection : A Practical Exploration CheatSheet #cybersec #infosec #websec #appsec #blindsql #cheatsheet #bugbounty

sumit_cfe's tweet image. Blind SQL Injection : A Practical Exploration CheatSheet

#cybersec #infosec #websec #appsec #blindsql #cheatsheet #bugbounty

I nearly missed a reflected XSS in United Nations Thanks for always posting tips and guiding new comers. @ADITYASHENDE17 @theXSSrat @ofjaaah writeup here: cysek.org/post/___b6 Hope you'll find it informative #websec #bugbounty #Pentesting #bugbountytips #bugbountywriteup

kab33rrr's tweet image. I nearly missed a reflected XSS in United Nations
Thanks for always posting tips and guiding new comers.
@ADITYASHENDE17
@theXSSrat @ofjaaah
writeup here: 
cysek.org/post/___b6

Hope you'll find it informative

#websec  #bugbounty #Pentesting #bugbountytips #bugbountywriteup

This year’s swag is lit 🔥 🔥 Huge thanks to @msftsecresponse !! #bugbounty #websec #infosec

Fatnass1F1ras's tweet image. This year’s swag is lit 🔥 🔥

Huge thanks to @msftsecresponse !!

#bugbounty #websec #infosec

Catch our next session with @_smile_hacker_ on "Request Smuggling and Its Exploitation"! Dive into how this web vulnerability works and how to defend against it. RSVP: null.community/events/1025-ah… #CyberSecurity #WebSec @null0x00 #nullahm

NullAhm's tweet image. Catch our next session with @_smile_hacker_  on "Request Smuggling and Its Exploitation"! Dive into how this web vulnerability works and how to defend against it.

RSVP: null.community/events/1025-ah…

#CyberSecurity #WebSec @null0x00 #nullahm

Help me get to 900🥹🙏🏾 #websec #pentesterlab #cybersecurity

c1ph3rbnuk's tweet image. Help me get to 900🥹🙏🏾
#websec #pentesterlab #cybersecurity

How many likes to get a #pentesterlab pro membership?🥹



Good times and consecutive bounties achieved with @intigriti define professionalism #bugbountytip #CyberSec #websec

Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec
Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec
Hunter_Huzaifa_'s tweet image. Good times and consecutive bounties achieved with @intigriti  define professionalism

#bugbountytip #CyberSec #websec

I published an article on blind regular expression injection attack, which has not been considered well. Enjoy! #websec | "A Rough Idea of Blind Regular Expression Injection Attack" - diary.shift-js.info/blind-regular-…

y0n3uchy's tweet image. I published an article on blind regular expression injection attack, which has not been considered well. Enjoy! #websec | "A Rough Idea of Blind Regular Expression Injection Attack" - diary.shift-js.info/blind-regular-…

Pásele primo, estamos regalando #HackingFuel a.k.a café en nuestro stand 🤠 #Websec #Pwnterrey

_websec's tweet image. Pásele primo, estamos regalando #HackingFuel a.k.a café en nuestro stand 🤠 #Websec #Pwnterrey

Come on @espn do you really not see the problem here. You are likely using mixed http/https on your login dialog... #infosec #websec

kylegalbraith's tweet image. Come on @espn do you really not see the problem here. You are likely using mixed http/https on your login dialog... #infosec #websec

Logical Bugs are often invisible to scanners They live in the assumptions devs make Want to find them? Think like the app shouldn’t work Here are 6 strategies to uncover logic bugs (with examples): #bugbounty #websec #cybersecurity

ReconOne_bk's tweet image. Logical Bugs are often invisible to scanners
They live in the assumptions devs make
Want to find them? Think like the app shouldn’t work

Here are 6 strategies to uncover logic bugs (with examples):
#bugbounty #websec  #cybersecurity

Loading...

Something went wrong.


Something went wrong.


United States Trends