n1nj4sec's Avatar

n1nj4sec

@n1nj4sec

Hacker | Bug Bounty Hunter

390
Followers
85
Following
3
Posts
27.11.2024
Joined
Posts Following

Latest posts by n1nj4sec @n1nj4sec

Preview
FreeMarker SSTI tricks FreeMarker SSTI tricks. GitHub Gist: instantly share code, notes, and snippets.

I recently found a blind FreeMarker SSTI on a bbp. It was not possible to RCE but I found some nice gadgets to enumerate accessible variables, read data blindly or perform some DoS. I documented that here if someone is interested
gist.github.com/n1nj4sec/5e3...

18.12.2024 20:13 ๐Ÿ‘ 12 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions.

I'm not gonna recite them again here, but today a new condition came up:

No Content-Type header -> no CSRF restrictions
Same-site: None
POST
= CSRF

The research:

27.11.2024 16:55 ๐Ÿ‘ 41 ๐Ÿ” 5 ๐Ÿ’ฌ 4 ๐Ÿ“Œ 0

๐Ÿ‘‹

27.11.2024 20:10 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

wow crazy trick !! thank you for sharing this Justin

27.11.2024 19:58 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0