Bug Bounty - Session Takeover in BMW Shops via XSS - HackerOne
Description Details removed due to change of report status (N/A to open) https://hackerone.com/reports/840871
Description Details removed due to change of report status (N/A to open) https://hackerone.com/reports/840871

Vulnerability Details Vendor: TM Mobile Solutions app@testes-codigo.pt Product: “Testes de Código” Mobile Application (Android & iOS) About: The mobile application “Testes de Código” (tdc.te...

Introduction The Portuguese Army (Exército Português) performs operational training on cyberdefense every year. This exercice is designated as “Ciber Perseu” and the 9th edition was held in Novemb...

Introduction This challenge was presented at DragonCTF 2020 organized by Dragon Sector, a capture-the-flag team from Poland. As the description suggests, we are given an executable that works on A...

Introduction This challenge is based on vm2.ova file which is used by virtualization applications such as Oracle VM Virtualbox and VMWare Workstation. Description makes reference to OpenBSD operat...

Introduction This week Microsoft released an update for CVE-2020-1350 (SIGRed), a Remote Code Execution vulnerability that affects Windows Server versions from 2003 to Server 2019. It was assigne...

Introduction This easy challenge requires analyzing a PE32 executable file by reversing it and find a buffer overflow vulnerability in order to achieve RCE. We are given an IP address, instead of ...

Introduction Some programs were made public in HackerOne bug bounty platform last month, including Alibaba Group Bug Bounty Program. After having a look at their program details I’ve noticed they ...

Introduction For a long time, Google search is being used by hackers to find specific elements on web applications by building customized queries containing advanced search operators. Using search...

Discovery Starting with one initial Nmap scan. It shows open ports running the following services: This is a Windows box. MySQL service listening on port 3306 was not recognized. However, Nmap ...