Found a cool bug at Meta.
From misconfigured Grafana instance to R/W access on 507 private Meta repositories.
Wrote up the full chain here:
sectricity.com/blog/misconfi…
$157k bounty awarded by @metabugbounty
Tien jaar geleden werd ik aangeklaagd voor het melden van een kwetsbaarheid in een Belgisch bedrijf.
Vanaf morgen is België het eerste land ter wereld waar testen zonder toestemming niet langer strafbaar is. Mooi moment om mijn 'strafblad' in te kaderen!
Meer nieuws morgen!
We are gearing up for our 2nd international live hacking event! We are super excited to have talented people like @TomNomNom join us! #HackWithIntigriti#1337UP1119
There has been some really awesome .NET research done recently, this whitepaper is a great reference when you come across .NET deserialization bugs/when code auditing. Machines running .NET have just become so much easier to own: nccgroup.trust/au/our-resear…
Last week we organized our first Howest Student CTF. Now that we've all got the chance to catch up on the missed sleep it is time for a recap of the event!
insecurity.be/blog/2019/03/2…
Those moments where you're working with loops, lengths and indexes and you know how to do the 1 or -1, 0 based or 1 based math shizzle, but you're too lazy to perform the mental effort so you end op typing whatever and seeing if it works out or not.
Upcoming @owasp_be chapter meeting in Bruges on October 23 with @pdcremer and Nathan Desmet on Distributing Software Security Knowledge, and @PhilippeDeRyck on API Security Pitfalls ... RSVP at owasp-belgium-2018-10-23.eve…