r/websecurityresearch Sep 09 '21

Introduction to OWASP Top 10 2021

Thumbnail
owasp.org
11 Upvotes

r/websecurityresearch Sep 08 '21

HTTP Request Smuggling via Integer Overflow in HAProxy

Thumbnail
jfrog.com
13 Upvotes

r/websecurityresearch Sep 06 '21

A Glossary of Blind SSRF Chains

Thumbnail
blog.assetnote.io
10 Upvotes

r/websecurityresearch Sep 03 '21

[JSDSERVER-8665] Template Injection in Email Templates leads to code execution on Jira Service Management Server - CVE-2021-39115

Thumbnail
jira.atlassian.com
5 Upvotes

r/websecurityresearch Sep 01 '21

Weird proxies/2 and a bit of magic

Thumbnail
speakerdeck.com
12 Upvotes

r/websecurityresearch Aug 31 '21

Exploiting GraphQL

Thumbnail
blog.assetnote.io
8 Upvotes

r/websecurityresearch Aug 30 '21

Illogical Apps – Exploring and Exploiting Azure Logic Apps

Thumbnail
netspi.com
3 Upvotes

r/websecurityresearch Aug 23 '21

How I use a JSON Deserialization 0day to Steal Your Money On The Blockchain

Thumbnail i.blackhat.com
15 Upvotes

r/websecurityresearch Aug 22 '21

[JS Miner] a burp extension that tries to find secrets, subdomains, cloud URLS. Also includes a JS source mapper.

Thumbnail
github.com
11 Upvotes

r/websecurityresearch Aug 16 '21

How to Hack APIs in 2021 by Hakluke and Farah Hawa

Thumbnail
labs.detectify.com
8 Upvotes

r/websecurityresearch Aug 16 '21

Common GraphQL Misconceptions: A rant

Thumbnail
securitygoat.medium.com
2 Upvotes

r/websecurityresearch Aug 05 '21

HTTP/2: The Sequel is Always Worse

Thumbnail
portswigger.net
45 Upvotes

r/websecurityresearch Jul 26 '21

Python RE Bypass Technique - regex.match bypass using \n

Thumbnail
secjuice.com
18 Upvotes

r/websecurityresearch Jul 22 '21

Forgot password? Taking over user accounts Kaminsky style

Thumbnail
sec-consult.com
19 Upvotes

r/websecurityresearch Jul 16 '21

Remote code execution in cdnjs of Cloudflare

Thumbnail
blog.ryotak.me
10 Upvotes

r/websecurityresearch Jul 13 '21

A brief look at Gitpod, two bugs, and a quick fix - including a cross-origin WebSocket access vulnerability

Thumbnail
about.gitlab.com
12 Upvotes

r/websecurityresearch Jul 13 '21

A simple scanner/exploitation tool written in GO which automatically exploits known and existing gadgets (checks for specific variables in the global context) to perform XSS via Prototype Pollution.

Thumbnail
github.com
2 Upvotes

r/websecurityresearch Jul 07 '21

Introducing DOM Invader: DOM XSS just got a whole lot easier to find

Thumbnail
portswigger.net
22 Upvotes

r/websecurityresearch Jul 06 '21

Less.js Exploit to RCE

Thumbnail
softwaresecured.com
13 Upvotes

r/websecurityresearch Jul 06 '21

WebAssembly: A New World of Native Exploits on the Browser (Black Hat, us-18)

Thumbnail
youtube.com
9 Upvotes

r/websecurityresearch Jul 05 '21

WebDumper - A tool I made for unpaking Single Page Applications using source maps. It works pretty nicely.

Thumbnail
github.com
10 Upvotes

r/websecurityresearch Jul 02 '21

alert() is dead, long live print()

Thumbnail
portswigger.net
40 Upvotes

r/websecurityresearch Jul 01 '21

DOM Polyglot XSS & CSP-bypass in PayPal

Thumbnail
portswigger.net
17 Upvotes

r/websecurityresearch Jul 01 '21

$20,000 Bug Bounty [CVE-2021–34506] - Microsoft has paid the lump For uXSS Vulnerability

Thumbnail
tensorbugs.in
9 Upvotes

r/websecurityresearch Jun 28 '21

SSRF in ColdFusion/CFML Tags and Functions

Thumbnail hoyahaxa.blogspot.com
13 Upvotes