Andrei Scutariu
@xnand_
cybersecurity something
ID: 2768136599
12-09-2014 18:11:46
27 Tweet
256 Followers
289 Following
I published the writeup of "Exploiting Hibernate Injection (HQL) in "Order by" Clause (Oracle database)" which we found during an assessment. mannulinux.org/2023/03/exploi… Special Thanks to: Soroush Dalili sir and Noman Riffat bhai ji #injection #websecurity #bugbountytips #Pentesting
Nicolas Krassas This project is backdoored and fake. DO NOT RUN THIS POC! For an example, here is their exploit for CVE-2023-20871: github.com/ChriSanders22/… That code looks very similar hmm....