Identifying and Exploiting Unsafe Deserialization in Ruby |
|
|
|
What do Netcat, SMTP and self XSS have in common? Stored XSS |
|
|
|
Account takeover using IDOR and the misleading case of error 403. |
|
|
|
Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over |
|
|
|
Duplicate but still cool |
|
|
|
IDOR in JWT and the shortest token you will ever see {}.{“uid”: “1234567890”} |
|
|
|