понеделник, 25 ноември 2019 г.

Category: static code analysis ↳ https://ift.tt/2QJXr7i Estimated...

Category: static code analysis

https://shells.systems/category/static-code-analysis/

Estimated Reading Time: 7 minutes Summary about FusionPBX FusionPBX can be used as a highly available single or domain based multi-tenant PBX, carrier grade switch, call center server, fax server, voip server, voicemail server, conference server, voice application server, appliance framework and mor…



from Hack+ https://ift.tt/33kEKcQ
via IFTTT

вторник, 19 ноември 2019 г.

avicoder on Twitter ↳ https://twitter.com/avicoder/status/1196796321945931776 I’ve started...

avicoder on Twitter

https://twitter.com/avicoder/status/1196796321945931776

I’ve started maintaining the list in scope urls of all public @Hacker0x01 programs. Can be consumed in lot of automation tools Check it out here: #togetherwehitharder…



from Hack+ https://ift.tt/2XCUbMB
via IFTTT

петък, 8 ноември 2019 г.

ctf-writeups ↳ https://ift.tt/2pL8ORv ctf-writeups Google CTF Finals 2019 Pwn...

ctf-writeups

https://github.com/netanel01/ctf-writeups

ctf-writeups Google CTF Finals 2019 Pwn Gomium…



from Hack+ https://ift.tt/2WUVvd4
via IFTTT

Developers: It’s super easy to bypass Android’s hidden API restrictions ↳...

Developers: It’s super easy to bypass Android’s hidden API restrictions

https://www.xda-developers.com/android-development-bypass-hidden-api-restrictions/

Flashback to over a year ago, and we’re all excited about seeing what’s to come in the Android P betas. Users are looking forward to new features, and developers are looking forward to some new tools to make their apps better….



from Hack+ https://ift.tt/2WXFjaZ
via IFTTT

Bypassing GitHub’s OAuth flow ↳...

Bypassing GitHub’s OAuth flow

https://blog.teddykatz.com/2019/11/05/github-oauth-bypass.html

For the past few years, security research has been something I’ve done in my spare time. I know there are people that make a living off of bug bounty programs, but I’ve personally just spent a few hours here and there whenever I feel like it….



from Hack+ https://ift.tt/2CDgd8h
via IFTTT

A Deep Dive On The Most Critical API Vulnerability ↳...

A Deep Dive On The Most Critical API Vulnerability

https://medium.com/@inonst/a-deep-dive-on-the-most-critical-api-vulnerability-bola-1342224ec3f2

In this article I dig into the details about Broken Object Level Authorization (BOLA) — the most common and most severe API vulnerability today according to the OWASP API Security Project. Insecure Direct Object Reference (IDOR) and BOLA are the same thing….



from Hack+ https://ift.tt/36JPnce
via IFTTT