Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 h1-ctf: [H1-2006 2020] "Swiss Cheese" design style leads to helping Mårten Mickos pay poor hackers

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 h1-ctf: [H1-2006 2020] "Swiss Cheese" design style leads to helping Mårten Mickos pay poor hackers


💡 Newskategorie: Sicherheitslücken
🔗 Quelle: vulners.com


image
Summary: Several vulnerabilities in the bountypay application leads to unauthorised access, information disclosure, SSRF and other fun stuff. Steps To Reproduce: This is how I helped Mårten Mickos pay the poor hackers who had been waiting so long for their bounties. First part: Web I started by finding all subdomains for challenge: https://bountypay.h1ctf.com https://app.bountypay.h1ctf.com https://staff.bountypay.h1ctf.com https://api.bountypay.h1ctf.com https://www.bountypay.h1ctf.com https://software.bountypay.h1ctf.com Fuzzing the subdomains, I found this: https://app.bountypay.h1ctf.com/.git/HEAD Checking /.git/config showed the link to the github repo and an interesting file: https://github.com/bounty-pay-code/request-logger/blob/master/logger.php which referenced the file bp_web_trace.log which could be found here: https://app.bountypay.h1ctf.com/bp_web_trace.log Decoding the contents of that file gave: {"IP":"192.168.1.1","URI":"\/","METHOD":"GET","PARAMS":{"GET":[],"POST":[]}} {"IP":"192.168.1.1","URI":"\/","METHOD":"POST","PARAMS":{"GET":[],"POST":{"username":"brian.oliver","password":"V7h0inzX"}}} {"IP":"192.168.1.1","URI":"\/","METHOD":"POST","PARAMS":{"GET":[],"POST":{"username":"brian.oliver","password":"V7h0inzX","challenge_answer":"bD83Jk27dQ"}}} {"IP":"192.168.1.1","URI":"\/statements","METHOD":"GET","PARAMS":{"GET":{"month":"04","year":"2020"},"POST":[]}} This looked like a server log which included credentials for the user 'brian.oliver', plus a... ...



📌 Marten Mickos wants to let a million hackers loose on corporate America


📈 59.95 Punkte

📌 Marten Mickos wants to let a million hackers loose on corporate America


📈 59.95 Punkte

📌 Newsmaker Interview: Marten Mickos on the Future of Bug Bounty


📈 54.5 Punkte

📌 An Interview With HackerOne CEO, Mårten Mickos


📈 54.5 Punkte

📌 Mårten Mickos: Why I Joined HackerOne as CEO


📈 54.5 Punkte

📌 An Interview With HackerOne CEO, Mårten Mickos


📈 54.5 Punkte

📌 Mårten Mickos: Why I Joined HackerOne as CEO


📈 54.5 Punkte

📌 An Interview With HackerOne CEO, Mårten Mickos


📈 54.5 Punkte

📌 Mårten Mickos: Why I Joined HackerOne as CEO


📈 54.5 Punkte

📌 Swiss banking software has Swiss cheese security, says Rapid7


📈 45.73 Punkte

📌 Swiss electronic voting system like... wait for it, wait for it... Swiss cheese: Hole found amid public source code audit


📈 45.73 Punkte

📌 T-Mobile Spectrum Auction Win Helps It Solve 'Swiss Cheese' Network Problem


📈 34.08 Punkte

📌 Microsoft pins hopes on AI once again – this time to patch up Swiss cheese security


📈 34.08 Punkte

📌 Swiss cheese security? Play ransomware gang milks government of 65,000 files


📈 34.08 Punkte

📌 Why Poor People Make Poor Decisions


📈 30.21 Punkte

📌 Poor Management of Security Certificates and Keys Leads to Preventable Outages


📈 27.83 Punkte

📌 Cheap Android Phones and Poor Quality Control Leads to Malware Surprise


📈 27.83 Punkte

📌 DEF CON Safe Mode Voting Village - Martin Mickos - See Something, Say Something


📈 27.03 Punkte

📌 Logitech: Privilege Escalation Leads to Control The Owner Access Token Which leads to control the stream [streamlabs.com]


📈 25.44 Punkte

📌 Whatsapp Pay gestartet: So sieht der neue Bezahldienst aus, mit dem Whatsapp Apple Pay und Google Pay angreift


📈 23.07 Punkte

📌 Whatsapp Pay gestartet: So sieht der neue Bezahldienst aus, mit dem Whatsapp Apple Pay und Google Pay angreift


📈 23.07 Punkte

📌 Financial asset firm PCI ordered to pay $1.5 million for poor cybersecurity practices


📈 22.79 Punkte

📌 Hey, pull your nose out of BlackBerry's poor financials and pay attention to this all-singing security doodah


📈 22.79 Punkte

📌 Hard work and poor pay stresses out open-source maintainers


📈 22.79 Punkte

📌 CryptoMix Ransomware – Tricks Users to Pay Ransom for Helping Children


📈 21.07 Punkte

📌 From this interview it seems that Purism will consider an elementaryOS-style pay-what-you-want model for the PureOS Store


📈 19.71 Punkte

📌 WordPress Design Flaw + WooCommerce Vulnerability Leads to Site Takeover


📈 18.86 Punkte

📌 Linux Study Argues Monolithic OS Design Leads To Critical Exploits


📈 18.86 Punkte

📌 Man faces up to 35 years in prison for helping hackers evade detection by anti-virus software


📈 18.84 Punkte

📌 Journalist Matthew Keys gets 2-Year Prison term for helping Anonymous Hackers


📈 18.84 Punkte

📌 Journalist Matthew Keys gets 2-Year Prison term for helping Anonymous Hackers


📈 18.84 Punkte

📌 ISPs May Be Helping Hackers to Infect you with FinFisher Spyware


📈 18.84 Punkte

📌 Ex-US Intelligence Agent Charged With Spying and Helping Iranian Hackers


📈 18.84 Punkte

📌 How Hackers Are Helping Fight Coronavirus - ThreatWire


📈 18.84 Punkte











matomo