You are here |
buer.haus | ||
| | | |
positive.security
|
|
| | | | Using a still unpatched vulnerability in the PHP library dompdf (used for rendering PDFs from HTML), we achieved RCE on a web server with merely a reflected XSS vulnerability as entry point. | |
| | | |
www.nodejs-security.com
|
|
| | | | Getting hands-on with SSRF bypasses and the pitfalls of denylists. | |
| | | |
chefsecure.com
|
|
| | | | Ever hear of Ruby on Rails? Here's how I hacked it for a $500 bounty! The JavaScript escaping used by Rails developers is missing protections for a common feature that's been around for over 5 years! | |
| | | |
www.silvestar.codes
|
|
| | It is the beginning of the new year, and it is time to look back to 2018, but from a technology perspective. I have learned a lot, here are my findings. |