Spotted a reverse engineering boutique at Zurich main station
Spotted a reverse engineering boutique at Zurich main station
It's amusing to me the amount of apps that implement pretty decent anti-SSRF measures:
- Private IP addresses✅
- Normalization of diff. IPv4/IPv6 representations✅
- TOCTOU DNS rebinding✅
- HTTP Redirects✅
But still this little😈 slips through the cracks:
- 0.0.0.0❌
#bugbountytips
Mass leakage
It's just like that sometimes
Swag's here! As part of an active campaign from 12build program run by @intigriti.com, I managed to find a few cool bugs. Great program, good quality💯 t-shirts
#bugbountytips
Part 8:
Part 7:
Anytime
Exactly, that would show the impact of port scanning yeah, now if you manage to exploit that service because of a vulnerability present on that version, obviously that would mean a increase of severity
Absolutely, those would be consider semi blind ssrf if you get any indication that you hit an open port, closed, etc. You need to prove the different behavior of those so the triager can be sure it's vulnerable actually routing requests to internal assets
Thank you! There isn't lol just the verification of hitting internal network
Part 6:
Devs☕
ical :)
Part 5:
Bypass anti-SSRF measures with redirects
Part 4:
Part 3:
12321737123612 OS payload
Os Inception
Ssrf output
Part 2:
SSRF output
I'm starting a new series called: Weird SSRF outputs
Hacking is just a weird thing that many discover because it's just something that we inherent (at birth?) and then develop over the years.
It just feels right to be around computers and entangled stuff that most of the time, u cannot wrap your head around it, but guess what? That's the beauty of it
Congrats!
Sometimes all it takes is one weird byte.
REcollapse aims to find it!
Just give it a URL and it will generate a fuzzing list for all regex pivot positions with all possible bytes %00 to %ff!
Check it 👇
That's impressive! The consistency is everything, no doubt.
Just as a pointer, at the very end the correct way is "ha sido *muy* útil".
- Mucho is like a quantifier.
- Muy is like an "emphasizer", e.g. Pretty good = *Muy* bueno.
This is the bad thing about sharing testing environments. This guy has been hammering an HTMLi on a invitation email request for three days now, which I'm 99.9% sure has been reported before **several times**.
I feel sorry for triagers seeing this type of... Thing on bug bounty reports
Well done guys!
Antimatter is cool and it's a real thing. I used to work on an experiment where we collided protons with antiprotons to make top-antitop quark pairs (among other things). ⚛️
The entire model handed to you
I would do the exact same thing :)