Jake Miller
@thebumblesec
Web Security Researcher | h2c smuggling, JSON Interop vulns,
RMIScout, GadgetProbe, Server-side Spreadsheet Injection | AppSec @BrexHQ; formerly @BishopFox
ID: 861328358
https://thebumble.io/ 04-10-2012 12:38:37
438 Tweet
2,2K Takipçi
384 Takip Edilen
I Own your Cloud Shell... Taking over “Azure Cloud Shell” Kubernetes Cluster Through Unsecured Kubelet API hencohen10.medium.com/i-own-your-clo… [30,000$ Bug Bounty] via Chen Cohen
JSON Interoperability vulnerabilities sound like they have some serious bug-bounty potential. Nice work once again by Jake Miller/Bishop Fox labs.bishopfox.com/tech-blog/an-e…
Istio vulnerability with an 8.2 CVSS. They're calling it a 0day. Also a lesson in JWT validation mistakes. > If a JWT token is presented with an issuer that does not match the issuer field specified in JwtProvider, then the request is mistakenly accepted groups.google.com/g/envoy-securi…
More great lessons on fuzzing from Antonio Morales! I am always excited when I see a new post in this series. Thank you for sharing!
Great research by Michael Stepankin! Also, be sure to check out the labs and updates to content at portswigger.net/web-security/o…
Amazing work James Kettle! I’m just blown away with your creativity in finding new desync variants. I’m looking forward to trying it out in the labs.