⚡️New DNS Out-of-Band vector for MSSQL Injections in SELECT statement! Can be used for completely blind #sqli.
Use fn_trace_gettable and #Burp Collaborator👍.
#ptswarmTechniques
Ситуация конечно пиздец хуевая! Итак понятно чем это всё закончится. Был вчера на суде и просто охуевал с этого сборища долбоебов. Админ сайта это идиот не разбирющийся вообще не в чем. Вся эта хуйня нужна была мусорам которые на суд даже не явились. 45.ru/text/criminal/69480651…
Hell, I thought the FSB in my country were tough guys in masks, but hell, how wrong I was, it's just ridiculous. They wring out my laptop from which I searched for errors, participate in Bug bounty programs.
My country is a country of Fuckers, where the secret services are engaged in all sorts of nonsense! Instead of trying to catch terrorists, they catch hackers for the fact that they participate in a bug bounty.
1/ The next time Establishment Democrats trash Bernie while pointing out that HRC won the popular vote against Donald Trump in the general election, you might want to remind them of a few things.
A Thread
Pretty nice there's a shell on the USB port of the @NorthSec_io badge this year. Don't forget there is BLE too and the embedded debugger (gdb stub). Much i/o.
Here are my slides for "Cache Me If You Can: Messing with Web Caching", presented @AppSecCali & @NorthSec_io! 🎉
Material includes:
- Web Caching 101
- Web Cache Deception
- Edge Side Include Injection
- Web Cache Poisoning
...with real bugs showcased!
drive.google.com/open?id=19I…