Bo0oM (@i_bo0om) 's Twitter Profile
Bo0oM

@i_bo0om

Web application security researcher

@sploitus_com

ID: 343490952

linkhttps://t.me/webpwn calendar_today27-07-2011 17:13:02

6,6K Tweet

4,4K Followers

784 Following

Aleksei Tiurin (@antyurin) 's Twitter Profile Photo

My small research about attacks on remote debuggers of various languages acunetix.com/blog/web-secur… #bugbountytips #Pentesting

PT SWARM (@ptswarm) 's Twitter Profile Photo

🐞PoC for a boolean-based #SQLi in Rapid7 Nexpose <= 6.6.48 (CVE-2020-7383) https://nexpose.local:3780/data/discoveryAsset/config/folderPath?path=[sqli]

🐞PoC for a boolean-based #SQLi in Rapid7 Nexpose &lt;= 6.6.48 (CVE-2020-7383)

https://nexpose.local:3780/data/discoveryAsset/config/folderPath?path=[sqli]
Emil Lerner (@emil_lerner) 's Twitter Profile Photo

Here're slides from my talk at ZeroNights X! A 0-day for GhostScript 9.50, RCE exploit chain for ImageMagick with the default settings from Ubuntu repos and several bug bounty stories inside slideshare.net/neexemil/hotpi…

Steph (@w34kp455) 's Twitter Profile Photo

Weakpass 3 is out - better rates, more wordlists, more functionality, and an All-in-One wordlist! Little presentation about what has changed youtu.be/tuiXmSehAFM #passwords

PT SWARM (@ptswarm) 's Twitter Profile Photo

💥 New article "Fuzzing for XSS via nested parsers condition" by our researcher Psych0tr1a. This techniques allowed us to find a bunch of vulnerabilities in popular web products that no one had noticed before! swarm.ptsecurity.com/fuzzing-for-xs…

Emil Lerner (@emil_lerner) 's Twitter Profile Photo

I just posted a write-up on how I leaked uninitialized memory (e.g., other users' HTTP requests/responses) from Fastly using a bug in the H2O webserver. Also, there you can learn a fraction of how HTTP/3 + QUIC works) medium.com/@emil.lerner/l…

Cure53 (@cure53berlin) 's Twitter Profile Photo

Bye bye, XSS, your time has finally come. // this is safe by default document.body.setHTML('unsafe HTML here') Firefox: about:config#dom.security.sanitizer.enabled Chrome: chrome://flags#enable-experimental-web-platform-features More info here: wicg.github.io/sanitizer-api/…

Kaimi & d_x (@kaimi_io) 's Twitter Profile Photo

Article from the previous post translated in English. 20 years of #payment processing problems kaimi.io/en/2022/07/20-… #security #pentest #paypal #steam #yoomoney #webmoney #racecondition #vulnerabilities