
Th3Wolf
@0xth3wolf
Cybersecurity enthusiast |Bug bounty | Sharing my journey || Securing the world.
ID: 1660716354666635284
22-05-2023 18:37:16
171 Tweet
38 Followers
672 Following



People miss critical vulnerabilities because they assume a GET request can't have a body This is how you can send such a request using #curl: $ curl '0.0.0.0:1234/download?filename=TEST' --data 'filename=../../../../../../../etc/passwd' -X GET By:PentesterLab #bugbountytips










Breaking In: How RXSS and SQLi Can Lead to Full Account Takeover and Database Access Thanks to all the security researcher for their awesome tools and automation. Credits: KNOXSS / XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky) Somdev Sangwan Egor Dimitrenko blog.bhuwanbhetwal.com.np/breaking-in-ho…



Cert Exam Voucher Giveaway provided by Ablative Technologies Prizes: 1 Security+ exam voucher 1 CCNA exam voucher How to enter: - RT - comment which voucher you want Winner will be picked next week. Good luck!





