never worry about remembering port numbers again! or running out of ports, or accidentally exposing internal services, or SSRF, or...
never worry about remembering port numbers again! or running out of ports, or accidentally exposing internal services, or SSRF, or...
gist.github.com/lirantal/297...
gist.github.com/lirantal/297...
atproto-labsはいつか正式版に昇格すんのかな
SSRF: PDF iframe Injection
Cheers!
SSRF: PDF iframe Injection
Cheers!
The agents: “so I named the file hack.rb,”
The agents: “so I named the file hack.rb,”
www.npmjs.com/package/ssrf...
www.npmjs.com/package/ssrf...
And that the answer usually upsets people.
And that the answer usually upsets people.
Check out my guide on GETTING HANDS-ON WITH SSRF bypasses and the pitfalls of denylists:
Check out my guide on GETTING HANDS-ON WITH SSRF bypasses and the pitfalls of denylists:
create an api in your appview that does domain verification
all it does is it gets a domain and checks if that domain is claimed and still valid in your db
app.get("/api/check-domain") => domain = c.req.query("domain")
ssrf: server side request forgery, lets you use a different computer (server) to pass messages/traffic
package manager: app store for coders
CVE: security bug
artifactory: a common package manager
0-day: a security bug nobody else knows about yet (which makes it useful)
youtu.be/87DyyMV0kCY
ssrf: server side request forgery, lets you use a different computer (server) to pass messages/traffic
package manager: app store for coders
CVE: security bug
artifactory: a common package manager
0-day: a security bug nobody else knows about yet (which makes it useful)
Covering what we now call SQL Injection and SSRF (amongst other things) problems we're still trying to handle today laid out in a couple of paragraphs
phrack.org/issues/54/8#...
Covering what we now call SQL Injection and SSRF (amongst other things) problems we're still trying to handle today laid out in a couple of paragraphs
phrack.org/issues/54/8#...