Ayubali
@0xayub
Security Enthusiast | Web and Mobile Apps | Open Source ❣️
ID: 1275062276790218762
https://0xayub.gitbook.io/blog/ 22-06-2020 13:45:28
335 Tweet
311 Followers
232 Following
After being nerd sniped by this, and discussion with Frans Rosén, heres two alternative ways: x(""+{a:location=name}+"") x(""+new class b{toString=e=>location=name}+"")
Basecamp disclosed a bug submitted by Emil Lerner: hackerone.com/reports/2107680 - Bounty: $8,868 #hackerone #bugbounty
🔥 OAuth "token reuse" vulnerability An interesting OAuth attack technique by Aviad Carmel that reused OAuth tokens from a different app to fully takeover victim's account in many popular apps like Grammarly salt.security/blog/oh-auth-a… #bugbountytips #bugbounty #cybersecurity
Bhavuk Jain Yep, it’s a pretty neat feature offered by GitHub as part of the Secret Scanning Partner Program. AWS, Microsoft, Google and Slack are part of it. docs.github.com/en/code-securi…
OSINT TIP #246 🐛 Tired of googling for #BugBounty writeups, payloadartist made a little tool "Bug Bounty Hunting Search Engine" that lets you search writeups easily. BugBountyHunting.com Thanks for tip Rohit Kumar 👏🏻 #OSINT #cybersecurity #bugbountytips #infosec