热点直击-黑帽安全大会
HTTP2 相关攻击面
http://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Kettle-HTTP-The-Sequel-Is-Always-Worse.pdf
http://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Kettle-HTTP2-The-Sequel-Is-Always-Worse-wp.pdf
http://github.com/PortSwigger/http-request-smuggler
http://portswigger.net/research/http2
大胡子yyds~

Exchange日穿 by 橘子

橘子yyds~
漏洞报告
Facebook Messenger for android indirect thread deletion vulnerability.
Facebook iOS address bar spoofing –
HackerOne
#1273292 Internal Gitlab Ticket Disclosure via External Slack Channels
Snapchat
#727487 Bypass Rate Limits on app.snapchat.com API Endpoint via X-Forwarded-For Header
MTN Group
Slack
#375083 Private application files can be uploaded to Slack via malicious uploader
挖洞技巧
别想偷我源码:通用的针对源码泄露利用程序的反制(常见工具集体沦陷)
Mistuned Part 1: Client-side XSS to Calculator and More · CodeColorist
挖洞工具
http://github.com/PortSwigger/taborator
http://github.com/0xC01DF00D/Collabfiltrator
文字来源于- 火线 Zone-云安全社区,安全小天地只做文章分享,如有侵权,请联系站长删除















请登录后查看评论内容