unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Lookup: TryHackMe CTF Walkthrough
Lab link: https://tryhackme.com/room/lookupTitle: Test your enumeration skills on this boot-to-root...
2026-7-7 11:36:26 | 阅读: 41 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
username
thm
pwm
ssh
machine
JWTweak v2.1: A Guided, Offline Toolkit for Modern JWT Attacks
Paste a token, get a full attack plan — then execute it, entirely offline.JSON Web Tokens sit at the...
2026-7-7 11:35:53 | 阅读: 34 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
powers
sit
gap
scores
No Rules, No Locks: Firebase Misconfiguration and the Borrowers It Left Behind
Press enter or click to view image in full sizeFirebase security rules are opt-in. The default, for...
2026-7-7 11:35:41 | 阅读: 37 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
firebase
loan
firestore
stringvalue
googleapis
The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration.
A POST to IMDS may fail — but a redirect can quietly turn it into something else.This writeup docume...
2026-7-7 11:35:22 | 阅读: 45 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
imds
303
library
client
bigquery
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
There’s a browser property called window.name that’s easy to overlook because it behaves differently...
2026-7-7 11:35:7 | 阅读: 36 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
payload
akamai
403
backurl
Chaining a DOM XSS Sink, WAF Bypass, Cross-Origin Smuggling, and SDK Abuse into One Click Account…
There’s a browser property called window.name that’s easy to overlook because it behaves differently...
2026-7-7 11:35:7 | 阅读: 35 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
payload
akamai
403
backurl
BadSuccessor — Exploiting delegated Managed Service Accounts in Windows Server 2025
Understanding what is delegated Managed Service Accounts in Windows Server 2025, and how an unpatche...
2026-7-7 11:34:55 | 阅读: 42 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
dmsa
tryhackme
windows
tbyte
sizestep
Wazuh File Integrity Monitoring: Tracking Endpoint Modifications in Real Time
OverviewIn this project, I implemented File Integrity Monitoring (FIM) using Wazuh to detect file sy...
2026-7-6 06:34:23 | 阅读: 31 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
wazuh
monitoring
windows
fim
ossec
Mastering curl Commands Bug Bounty Hunter's Guide
Every bug bounty hunter has curl installed. Few use it to its full potential. While Burp Suite and c...
2026-7-6 06:30:13 | 阅读: 35 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
jq
uthis
shines
security
Mastering curl Commands Bug Bounty Hunter's Guide
Every bug bounty hunter has curl installed. Few use it to its full potential. While Burp Suite and c...
2026-7-6 06:30:13 | 阅读: 33 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
jq
stateless
subdomain
security
Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover
Press enter or click to view image in full sizeNo customer support call. No re-verification.Yet the...
2026-7-6 06:29:11 | 阅读: 36 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
insurance
attacker
mass
assignment
birth
Mass Assignment and the Identity Drift: From Profile Edit to Insurance Takeover
Press enter or click to view image in full sizeNo customer support call. No re-verification.Yet the...
2026-7-6 06:29:11 | 阅读: 25 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
insurance
attacker
mass
assignment
birth
The File That Answered Back — XXE Hidden in Cell A2
Press enter or click to view image in full sizeMost people know XXE. Few think to look for it inside...
2026-7-6 06:28:59 | 阅读: 39 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
xlsx
workbook
sheet1
windows
The File That Answered Back — XXE Hidden in Cell A2
Press enter or click to view image in full sizeMost people know XXE. Few think to look for it inside...
2026-7-6 06:28:59 | 阅读: 35 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
xlsx
workbook
windows
sheet1
RCE via Gemini Live AI Voice Session Misconfiguration.
Press enter or click to view image in full sizeSource: https://ai.google.dev/gemini-api/docs/live-ap...
2026-7-6 06:28:53 | 阅读: 34 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
gemini
client
constraints
bidi
expire
RCE via Gemini Live AI Voice Session Misconfiguration.
Press enter or click to view image in full sizeSource: https://ai.google.dev/gemini-api/docs/live-ap...
2026-7-6 06:28:53 | 阅读: 33 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
gemini
client
constraints
python
expire
How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues ch...
2026-7-6 06:28:43 | 阅读: 31 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
client
attacker
victim
verifier
pkce
How I Found a Critical OAuth Misconfiguration That Led to Account Takeover
A bug bounty story about OAuth, PKCE, open client registration, and how multiple low-level issues ch...
2026-7-6 06:28:43 | 阅读: 32 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
client
attacker
victim
pkce
verifier
How I Found a Data Deletion Bypass via Subdomain Synchronization
This is what I did after my lunch break and immediately got enough cash to buy stuff in the premium...
2026-7-6 06:28:9 | 阅读: 40 |
收藏
|
InfoSec Write-ups - Medium - infosecwriteups.com
subdomain
moderator
developer
deletion
How I Found a Data Deletion Bypass via Subdomain Synchronization
This is what I did after my lunch break and immediately got enough cash to buy stuff in the premium...
2026-7-6 06:28:9 | 阅读: 32 |
收藏
|
Bug Bounty in InfoSec Write-ups on Medium - infosecwriteups.com
subdomain
moderator
developer
destructive
Previous
5
6
7
8
9
10
11
12
Next