Shay
@shay_1337
Penetration Tester, Web Application Security
ID: 1363755115400855554
22-02-2021 07:39:05
570 Tweet
123 Followers
470 Following
Sharing a technical writeup, which goes over an almost year long responsible disclosure process: jdomeracki.github.io/2024/11/09/ske… The severity of disclosed shortcomings, resulted in googlecloudcheatsheet.withgoogle.com getting decommissioned 🚧 Greatly appreciate the cooperation with Google VRP (Google Bug Hunters)! 🎉
🎉 PESD v2.0 - now in the BApp Store ! Effortlessly generate dynamic sequence diagrams directly from #BurpSuite traffic! Now you can also create your own theme, conveniently edit generated diagrams with MD syntax and much more! Install it today! 🎉 #doyensec #appsec #security
Are you aware that any local admin on IIS boxes can see appPool identity creds in clear-text? Here's a script to map IIS Servers, appPools, vDirs, usernames & passwords, inc. insights on risk reduction and mitigation of this potential exposure: github.com/YossiSassi/Get… HackCon Norway
Suraj Matan Berson Heard the feedback: "The probability is so low—a user has to drag, drop, and click!?" But with AI agents soon browsing and acting for us (e.g., OpenAI operator), this becomes a 0-click XSS. Critical Thinking - Bug Bounty Podcast