0day work (@0daywork) 's Twitter Profile
0day work

@0daywork

A security blog by @gehaxelt

ID: 4098350038

linkhttp://0day.work calendar_today02-11-2015 16:02:57

104 Tweet

1,1K Takipçi

9 Takip Edilen

d3mondev (@d3mondev) 's Twitter Profile Photo

This is my new favorite wordlist for subdomain enumeration by Internetwache.org! It's updated hourly and sorted by number of occurrences. You can clean it up easily with sed to use with gobuster (or whatever floats your boat). 1/2 #bugbounty #hacking #osint github.com/internetwache/…

0day work (@0daywork) 's Twitter Profile Photo

New blogpost: Proof of Concept for "Apache Httpd Limited cross-site scripting in mod_proxy error page (CVE-2019-10092)" 0day.work/proof-of-conce… #cve #apache #httpd #xss

0day work (@0daywork) 's Twitter Profile Photo

New blog post: Proof of Concept for "Wordpress <=5.2.3: viewing unauthenticated posts" 0day.work/proof-of-conce… #wordpress #cve #writeup #infosec WPScan - WordPress Security #poc

New blog post: Proof of Concept for "Wordpress &lt;=5.2.3: viewing unauthenticated posts" 

0day.work/proof-of-conce…

#wordpress #cve #writeup #infosec <a href="/_WPScan_/">WPScan - WordPress Security</a> #poc
0day work (@0daywork) 's Twitter Profile Photo

New blogpost: Open Redirects In Improperly Configured mod_rewrite Rules (PoC for CVE-2019-10098?) 0day.work/open-redirects… #cve #cve_2019_10098 #apache #openredirect #mod_rewrite #configuration #sysadmin #security #infosec

0day work (@0daywork) 's Twitter Profile Photo

#BugBountyTip Always check for #RaceConditions when redeeming coupons to get greater discounts and huge bounties ;-) #Bugbounty #OWASP #ITSecurity

#BugBountyTip Always check for #RaceConditions when redeeming coupons to get greater discounts and huge bounties ;-)

#Bugbounty #OWASP #ITSecurity
0day work (@0daywork) 's Twitter Profile Photo

#Bugbountytip Look for #API keys in the documentation or screenshots of blog posts. Sometimes those are *not* (entirely) redacted and still valid employee's credentials, giving you access to some juicy endpoints ;-) #Bugbounty #OWASP #ITSecurity

#Bugbountytip Look for #API keys in the documentation or screenshots of blog posts.

Sometimes those are *not* (entirely) redacted and still valid employee's credentials, giving you access to some juicy endpoints ;-) 

#Bugbounty #OWASP #ITSecurity
0day work (@0daywork) 's Twitter Profile Photo

That's a nice admin login bypass issue. I have a PoC and write-up ready to release, but I'll wait a few days for people to update. #wordpress #security #bypass

0day work (@0daywork) 's Twitter Profile Photo

New blogpost: InfiniteWP Client < 1.9.4.5 - Authentication Bypass 0day.work/infinitewp-cli… Simply unauth. exploit to get admin access. #wordpress #security #itsec WPScan - WordPress Security

0day work (@0daywork) 's Twitter Profile Photo

New research and blogpost: Pwning your (web)server and network the easy way - or why exposing ~/.ssh/ is a bad idea 0day.work/pwning-your-we… #security #itsec #bugbounty #ssh #websecurity

New research and blogpost: 

Pwning your (web)server and network the easy way - or why exposing ~/.ssh/ is a bad idea

0day.work/pwning-your-we…

#security #itsec #bugbounty #ssh #websecurity
0day work (@0daywork) 's Twitter Profile Photo

New blog post: Files on web servers Part I: History Files 0day.work/files-on-web-s… #websecurity #security #owasp #bugbountytips #ITsecurity

Detectify (@detectify) 's Twitter Profile Photo

#Wordpress plugin vulns are reported to us w. good reason - millions of sites use them, which means millions of apps to secure. An analysis of from Crowdsource hacker, Sebastian Neef: #infosec #websecurity blog.detectify.com/2020/02/26/geh…

0day work (@0daywork) 's Twitter Profile Photo

Another blog post, but this time Detectify's blog: How Wordpress plugins leak sensitive information. It's also a great #bugbountytips :-)

0day work (@0daywork) 's Twitter Profile Photo

New blog post: Damn Vulnerable Bash Web Server - A web server written in bash. 0day.work/damn-vulnerabl… #bash #ctf #webserver #enowars #shittr

Sebastian Neef (@gehaxelt) 's Twitter Profile Photo

I'll be giving a talk at the virtual #HITBAMS20 / #HITBLockdown with my colleagues about "Open the Gates – The (in)security of Cloudless Smart Door Systems" Join the livestream at 2pm CET today! conference.hitb.org/lockdown-lives…

0day work (@0daywork) 's Twitter Profile Photo

New blogpost: Credentials hiding in plain sight or how I pwned your http auth 0day.work/credentials-hi… #bugbounty #security #ITSecurity

New blogpost: Credentials hiding in plain sight or how I pwned your http auth 

0day.work/credentials-hi…

#bugbounty #security #ITSecurity
Sebastian Neef (@gehaxelt) 's Twitter Profile Photo

Oh, forgot to post it here. I have a lightning talk at Detectify #Hackerschool 10 yesterday! Slides can be found here: 0day.work/credentials-hi… #Bugbounty