Тёмный

Match & Replace - HTTP Proxies' Most Underrated Feature (Ep. 76) 

Critical Thinking - Bug Bounty Podcast
Подписаться 9 тыс.
Просмотров 1,6 тыс.
50% 1

Episode 76: In this episode of Critical Thinking - Bug Bounty Podcast we’re talking about Match and Replace and the often overlooked use cases for it, like bypassing paywalls, modifying host headers, and storing payloads. We also talk about the HackerOne Ambassador World Cup and the issues with dupe submissions, and go through some write-ups.
Follow us on twitter at: / ctbbpodcast
We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io
Shoutout to / realytcracker for the awesome intro music!
====== Links ======
Follow your hosts Rhynorater & Teknogeek on twitter:
/ 0xteknogeek
/ rhynorater
====== Ways to Support CTBBPodcast ======
Hop on the CTBB Discord at ctbb.show/discord!
We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.
Resources:
Zoom Session Takeover
nokline.github.io/bugbounty/2...
SharePoint XXE
x.com/thezdi/status/179620701...
Shazzer
shazzer.co.uk/
Timestamps:
(00:00:00) Introduction
(00:05:06) H1 Ambassador World Cup
(00:13:57) Zoom ATO bug
(00:33:28) SharePoint XXE
(00:39:36) Shazzer
(00:46:36) Match and Replace
(01:13:01) Match and Replace in Mobile
(01:21:13) Header Replacements

Наука

Опубликовано:

 

29 июн 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 2   
@Morteums
@Morteums 7 дней назад
Cookie Bugs - Smuggling & Injection from Ankur Sundara, is that the paper you referenced ?
@Rhyn0r4t3r
@Rhyn0r4t3r 4 дня назад
Yep, that's the one.
Далее
Creator of HTMX Talks HTMX
1:02:41
Просмотров 168 тыс.
🎙️ПЕСНИ ВЖИВУЮ от КВАШЕНОЙ💖
3:23:13
Missing HTTP Security Headers - Bug Bounty Tips
15:48
Просмотров 137 тыс.
SWE Stop Learning - The Rise Of Expert Beginners
49:09
Просмотров 243 тыс.
Pretending to be a VM to STOP Malware
10:36
Просмотров 128 тыс.
An Excruciatingly Deep Dive into the Avatar Theme Park
59:01
15 Laptop BUYING MISTAKES! 2024 Laptop Buying Guide
10:01
🛑 STOP! SAMSUNG НЕ ПОКУПАТЬ!
1:00
Просмотров 62 тыс.
Самый СТРАННЫЙ смартфон!
0:57
Просмотров 34 тыс.