|
You are here |
labanskoller.se | ||
| | | | |
nv1t.github.io
|
|
| | | | | I've identified a security concern within the self-hosted file sharing tool ProjectSend in the current version r1605. By exploiting a chain of vulnerabilities - including Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), and weaknesses in its change password implementation - an authenticated attacker can force a logged-in user to unknowingly change their account password, by clicking a link. But let me explain the attack in detail. | |
| | | | |
mike.sherov.com
|
|
| | | | | Most websites offer personalized experiences powered by a "logged in" mode. In order to remember who a user is, sites place a cookie containing a unique... | |
| | | | |
alexsci.com
|
|
| | | | | A review of HSTS and HSTS preload list growth | |
| | | | |
fhirblog.com
|
|
| | | In this post I'm going to talk a little about REST - REpresentational State Transfer - in the context of FHIR. The FHIR specification goes into some detail about how REST and FHIR work together, so go there for more details. As mentioned in a previous post, FHIR works across many different interoperability paradigms, but... | ||