Загрузка видео...

Не удалось загрузить видео

На главную

I recently found a cool #RCE/path traversal bug on a target in Intigriti. It was rejected because of OoS :( But I am proud that I found this cool bug through a full manual testing of the endpoint. This video just simplifies the steps, but I took hours to...

38,890 просмотров • 2 лет назад •via X (Twitter)

Комментарии: 10

Фото профиля Kanhaiya Sharma 🇮🇳
Kanhaiya Sharma 🇮🇳2 лет назад

`id` `cat%20/etc/passwd` cmdi payloads #bugbountytips

Фото профиля N$
N$2 лет назад

🙏

Фото профиля bugoverflow
bugoverflow2 лет назад

Cool. What is software allow you redact the text :D?

Фото профиля N$
N$2 лет назад

Snagit + CapCut

Фото профиля NOB0dy
NOB0dy2 лет назад

Remind me of a web app I pentested where you could verify if a domain was registered or not. There was a filter in place, and I needed to use domain=example%3b`id`% to bypass it. It was unauth RCE xD the app was already pentested 4 times before me...

Фото профиля Ariff
Ariff2 лет назад

👏 👏 👏

Фото профиля Wip3r
Wip3r2 лет назад

nice job bro 😋

Фото профиля Shakti
Shakti2 лет назад

Congratulation sir

Фото профиля Ayadim
Ayadim2 лет назад

Thank you for sharing bro

Фото профиля st0x_r0
st0x_r02 лет назад

nice

Похожие видео