|
You are here |
sookocheff.com | ||
| | | | |
gist.github.com
|
|
| | | | | HTTP Archive data on `http-equiv` usage from June 2023 (Top 200) - http-equiv-data.csv | |
| | | | |
nv1t.github.io
|
|
| | | | | I've identified a security concern within the self-hosted file sharing tool ProjectSend in the current version r1605. By exploiting a chain of vulnerabilities - including Cross-Site Scripting (XSS), Insecure Direct Object Reference (IDOR), and weaknesses in its change password implementation - an authenticated attacker can force a logged-in user to unknowingly change their account password, by clicking a link. But let me explain the attack in detail. | |
| | | | |
blog.damnscout.com
|
|
| | | | | I didn't blog yesterday here, but I did tweet, and I did write code. It was late, but I still got stuff done. Today was an interesting day. I'm stillcoding, but I came across an interesting bug I'd like to share. So, in the code... | |
| | | | |
www.uptycs.com
|
|
| | | |||