Тёмный

$29,000 GitLab - Arbitrary File Read using symlinks 

Bug Bounty Reports Explained
Подписаться 55 тыс.
Просмотров 7 тыс.
50% 1

Наука

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 19   
@shaheenfazim
@shaheenfazim Год назад
The idea using symlinks is brilliant.
@kiedysbedemilionerem2414
@kiedysbedemilionerem2414 Год назад
Powodzenia z tym kanałem, robisz kozacką robotę
@BugBountyReportsExplained
@BugBountyReportsExplained Год назад
Dzięki! Powodzenia w zostaniu milionerem ;)
@mub1n
@mub1n Год назад
nicely explained
@e.donker7787
@e.donker7787 Год назад
Very interesting bug! Thanks for the clear explanation
@cyber-man
@cyber-man Год назад
Very cool new animations in the report explained (and sound effects too) - but I'm not so sure about the fish-eye camera, are u?
@BugBountyReportsExplained
@BugBountyReportsExplained Год назад
Thank you. Regarding the camera, it's not actually a fish-eye but a 35mm wide lens. But for this video, I not only sat too close to it but also out-of-focus which made it look quite bad and distorted. I'll figure it out better for the next time.
@bdsgameing9789
@bdsgameing9789 Год назад
I'm back for watching your videos
@snifyak
@snifyak Год назад
Awsm👍
@unurbayaramarsaikhan1362
@unurbayaramarsaikhan1362 Год назад
I'm appreciated for hard work.
@Al-rt3ec
@Al-rt3ec Год назад
I need how to get this bug bounty report in detail
@cryptowise658
@cryptowise658 Год назад
You are billionaire boy 🔥🔥
@BugBountyReportsExplained
@BugBountyReportsExplained Год назад
I'm not the one who found the bug unfortunately - all the credit goes to William Bowling
@matteo5076
@matteo5076 Год назад
This is basically zipslip, isn't it? Nonetheless it's an interesting finding!
@BugBountyReportsExplained
@BugBountyReportsExplained Год назад
afaik, zipslip (or tarslip) relies on embedding ../ in the filename
@allandiego1446
@allandiego1446 Год назад
Some lab?;
@revolutionstudio6385
@revolutionstudio6385 Год назад
Hello 👋
@BugBountyReportsExplained
@BugBountyReportsExplained Год назад
Hello 👋
@saurabhbhardwaj3427
@saurabhbhardwaj3427 Год назад
Good job bro
Далее
ЛОВИМ НОВЫХ МОНСТРОВ В LETHAL COMPANY
2:42:22
Hacking Websites by Uploading files (With symlinks)
7:50
📱магазин техники в 2014 vs 2024
0:41
S23 ultra screen 💥 #Fixit
1:01
Просмотров 4,6 млн