Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Also, Cursor can also connect to Caido’s proxy on localhost via its embedded browser when a proxy is needed, just saying 👀. Here it used the proxy to solve a traversal sequence that had been stripped by a superfluous URL-decode from PortSwigger Labs. #BugBounty #bugbountytip

16,613 Aufrufe • vor 11 Monaten •via X (Twitter)

5 Kommentare

Profilbild von H4x0r.DZ
H4x0r.DZvor 11 Monaten

btw, I wanted to say this a long time ago @CaidoIO uses an old, vulnerable version of Chromium 130.0.6723.0 . This version has public critical vulnerabilities , some of them with public POCs This means any script kiddies can hack you if you are using Caido by sending you a URL! I hope the team of @CaidoIO starts doing the patch management ASAP

Profilbild von Hazem
Hazemvor 11 Monaten

@CaidoIO As @sw33tLie said, since this was part of @PortSwigger labs the model was most likely already trained to find these, but that doesn't change the fact I discovered multiple real-world flaws using those tools/methods on bug-bounty targets 🤷‍♂️ Reference:

Profilbild von slonser
slonservor 10 Monaten

@cursor_ai @CaidoIO You also can download "Ebka AI" from the store and connect Caido as an MCP to Cursor

Profilbild von Jayesh Madnani
Jayesh Madnanivor 10 Monaten

@cursor_ai @CaidoIO Wild stuff. Can confirm 🫡😛

Profilbild von Hazem
Hazemvor 10 Monaten

@cursor_ai @CaidoIO

Ähnliche Videos