正在加载视频...

视频加载失败

Also, Cursor can also connect to Caido’s proxy on localhost via its embedded browser when a proxy is needed, just saying 👀. Here it used the proxy to solve a traversal sequence that had been stripped by a superfluous URL-decode from PortSwigger Labs. #BugBounty #bugbountytip

16,613 次观看 • 11 个月前 •via X (Twitter)

5 条评论

H4x0r.DZ 的头像
H4x0r.DZ11 个月前

btw, I wanted to say this a long time ago @CaidoIO uses an old, vulnerable version of Chromium 130.0.6723.0 . This version has public critical vulnerabilities , some of them with public POCs This means any script kiddies can hack you if you are using Caido by sending you a URL! I hope the team of @CaidoIO starts doing the patch management ASAP

Hazem 的头像
Hazem11 个月前

@CaidoIO As @sw33tLie said, since this was part of @PortSwigger labs the model was most likely already trained to find these, but that doesn't change the fact I discovered multiple real-world flaws using those tools/methods on bug-bounty targets 🤷‍♂️ Reference:

slonser 的头像
slonser10 个月前

@cursor_ai @CaidoIO You also can download "Ebka AI" from the store and connect Caido as an MCP to Cursor

Jayesh Madnani 的头像
Jayesh Madnani10 个月前

@cursor_ai @CaidoIO Wild stuff. Can confirm 🫡😛

Hazem 的头像
Hazem10 个月前

@cursor_ai @CaidoIO

相关视频