Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
infosec-au
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Vulnerable by Design: Server-Side Request Forgery (SSRF)
(bishopfox.com)
1 points
by
infosec-au
11y ago
|
0 comments
2.
▲
WPScan Licensing
(blog.dewhurstsecurity.com)
3 points
by
infosec-au
12y ago
|
1 comments
3.
▲
by
infosec-au
12y ago
Ah! Good idea! I'll implement it now :) The HipChat notifications go off at a fixed time (9AM and 9PM UTC) every day, however in the future I may add a feature to let people set the time the bot posts.
4.
▲
by
infosec-au
12y ago
I just released this, so unfortunately I don't have an archive (yet). However, you can view a fully filled example here: http://websecweekly.org/static/newsletters/example.html Thanks!
5.
▲
by
infosec-au
12y ago
Disclaimer: I'm the author of this. The source code for most of it can be found on github [1] and the motivation behind building it is documented on my blog [2]. I'm happy to answer questions and take any feedback :) Thanks all. [
6.
▲
Show HN: Websec Weekly – Newsletter for web security enthusiasts
(websecweekly.org)
29 points
by
infosec-au
12y ago
|
8 comments
7.
▲
Flaw Enabled Access to Internal Yahoo Administration Panel
(securityweek.com)
1 points
by
infosec-au
12y ago
|
0 comments
8.
▲
Critical bug in Parallels Plesk SSO (XXE Injection)
(makthepla.net)
1 points
by
infosec-au
12y ago
|
0 comments
9.
▲
by
infosec-au
12y ago
I don't think you understand, the PoC is not supposed to be a PoC for phishing but rather a PoC for their lack of rate limiting [1] , and user enumeration. I have showed the first name and last name [2], but have accordingly blurred th
10.
▲
by
infosec-au
12y ago
The actual bug report is the technical section of my blog post: http://blog.shubh.am/full-disclosure-coinbase-security/#tech... You're reading the Proof of Concept, which is meant to be a practical demonstration o
11.
▲
by
infosec-au
12y ago
Hey, I'm the author of this blog post. I think you're mistaken, I didn't send any phishing emails to anyone. All the emails were sent through coinbase via their request money featurein which I am trying to get them to fix. Al