Shebiiiii
@xshebix
Cyber Security Researcher - Red Team Member at Synack
ID: 802627943235289089
26-11-2016 21:39:48
3,3K Tweet
671 Takipçi
3,3K Takip Edilen
XSS with no parenthesis 🔥 Thanks to Justin Gardner for sending me this target with a really weird filter. It was a fun challenge 🤟 Btw I'm not the one that discovered the use of instanceof for XSS ;) #bugbountytips
we earned $20,000 for Our submission on @bugcrowd Tuan Anh Nguyen⚡️ 🇻🇳 Godfather Orwa 🇯🇴 It's nice to work with you guys :) #Tip: Always check `viewstate` In Asp. Net More Info : notsosecure.com/exploiting-vie… bugcrowd.com/hackerx007 #ItTakesACrowd
I’ve published the slides for my Security BSides Ahmedabad closing keynote: bit.ly/pwning-cloud-c… In this talk, I shared: “Lateral movement brute forcing” — a new technique that I covered and used against different targets to go, eg. From a limited GitHub token to achieve multi-lateral