Explore >> Select a destination


You are here

labanskoller.se
| | alexsci.com
4.8 parsecs away

Travel
| | A review of HSTS and HSTS preload list growth
| | educatedguesswork.org
4.3 parsecs away

Travel
| |
| | nv1t.github.io
4.4 parsecs away

Travel
| | I've identified a security concern within the self-hosted file sharing tool ProjectSend in the current version r1605. By exploiting a chain of vulnerabilities - including Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), and weaknesses in its change password implementation - an authenticated attacker can force a logged-in user to unknowingly change their account password, by clicking a link. But let me explain the attack in detail.
| | www.wired.com
18.8 parsecs away

Travel
| Plus: The US Marshals disclose a "major" cybersecurity incident, T-Mobile has gotten pwned so much, and more.