
Intigriti
@intigriti
Followers
191K
Following
16K
Media
3K
Statuses
12K
Bug bounty & VDP platform trusted by the worldβs largest organisations! π
Joined May 2016
Want to receive your copy in your inbox each month? π Subscribe to Bug Bytes now! π.
newsletter.intigriti.com
Receive the most exclusive hacking write-ups, tools & insider security research from the most notable bug bounty hunters in our community each month in your inbox! Subscribe now & join 125,000+...
1
0
8
@GodfatherOrwa @net_code @securitum_com @isec_pl That was it! We hope you've learned something new (and enjoyed) this thread!. If you have enjoyed this thread:.1. Follow us @INTIGRITI for more of these threads! π.2. Retweet the first Tweet to share it with your friends π.
0
0
6
@GodfatherOrwa @net_code @securitum_com 5οΈβ£ Beyond SSTI. @isec_pl shares their methodology for finding and identifying a server-side template injection in Craft CMS (PHP).
blog.isec.pl
From Server-side Template Injection to Remote Command Execution - a short story of the contact form analysis.
1
3
6
@GodfatherOrwa @net_code 4οΈβ£ JWT (JSON Web Token) (in)security. This in-depth article by @securitum_com dives deeper into how to test JSON web tokens (JWTs) to bypass authentication.
research.securitum.com
JWT (JSON Web Token) is a mechanism that is often used in REST APIs it can be found in popular standards, such as OpenID Connect, but we will also encounter it sometimes using OAuth2. It is used both...
1
1
7
@GodfatherOrwa @net_code 3οΈβ£ We Hacked Apple for 3 Months: Hereβs What We Found. A classic write-up by 5 talented researchers that briefly talked about their experience hacking Apple for 3 months!.
samcurry.net
Between the period of July 6th to October 6th myself, Brett Buerhaus, Ben Sadeghipour, Samuel Erb, and Tanner Barnes worked together and hacked on the Apple bug bounty program.
1
2
9
@GodfatherOrwa 2οΈβ£ EJS, Server side template injection RCE. @net_code shares how he discovered a template injection in EJS, including payloads and an escalation technique to achieve RCE!.
eslam.io
Note: The objective of this research or any similar researches is to improve the nodejs ecosystem security level. Recently i was working on a related project using one of the most popular Nodejs...
1
1
9
1οΈβ£ Your Full Map To Github Recon And Leaks Exposure. @GodfatherOrwa teaches how to perform advanced reconnaissance and spot vulnerabilities using GitHub search!.
orwaatyat.medium.com
Hello My Name Orwa Atyat
1
1
14
DomLoggerpp by @kevin_mizu is a simple web extension that helps you identify JavaScript DOM sinks that could lead to DOM-based vulnerabilities (such as XSS)! π . Check it out! π .π
1
54
264