Hacker Newsnew | past | comments | ask | show | jobs | submit | infosecau's submissionslogin
1.Frontier class vulnerabilities: it gets worse before it (maybe) gets better (shubs.io)
1 point by infosecau 31 days ago | past
2.I found a WordPress RCEs with GPT5.6 and $25 (slcyber.io)
404 points by infosecau 44 days ago | past | 227 comments
3.The down fall of bug bounties (shubs.io)
2 points by infosecau 3 months ago | past
4.High fidelity check for Next.js/RSC RCE (CVE-2025-55182 and CVE-2025-66478) (slcyber.io)
3 points by infosecau 9 months ago | past
5.Analyzing the Next.js Middleware Bypass (CVE-2025-29927) (slcyber.io)
2 points by infosecau on March 24, 2025 | past
6.So, you want to get into bug bounties? (shubs.io)
2 points by infosecau on Nov 26, 2022 | past
7.Exploiting Static Site Generators: When Static Is Not Static (assetnote.io)
21 points by infosecau on Nov 1, 2022 | past
8.Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) (assetnote.io)
1 point by infosecau on July 6, 2022 | past
9.Cloudflare Pages, part 1: The fellowship of the secret (assetnote.io)
28 points by infosecau on May 6, 2022 | past | 2 comments
10.Hacking a Bank by Finding a 0day in DotCMS (assetnote.io)
3 points by infosecau on May 5, 2022 | past
11.Eliminating Dangling Elastic IP Takeovers with Ghostbuster (assetnote.io)
2 points by infosecau on Feb 15, 2022 | past
12.Turning Bad SSRF to Good SSRF: Websphere Portal (assetnote.io)
2 points by infosecau on Dec 28, 2021 | past
13.Exploiting GraphQL (assetnote.io)
2 points by infosecau on Aug 30, 2021 | past
14.Taking over Uber accounts through voicemail (assetnote.io)
15 points by infosecau on July 4, 2021 | past | 5 comments
15.Hacking IIS (drive.google.com)
1 point by infosecau on March 20, 2021 | past
16.Attack of the clones: Git clients remote code execution (blazeinfosec.com)
5 points by infosecau on Nov 7, 2020 | past
17.Finding Hidden Files and Folders on IIS Using BigQuery (assetnote.io)
1 point by infosecau on Sept 20, 2020 | past
18.Hacking on Bug Bounties for Four Years (assetnote.io)
89 points by infosecau on Sept 17, 2020 | past | 10 comments
19.Taking over Azure DevOps accounts with one click (assetnote.io)
118 points by infosecau on July 1, 2020 | past | 25 comments
20.Expanding the Attack Surface: React Native Android Applications (assetnote.io)
37 points by infosecau on Feb 2, 2020 | past | 11 comments
21.CVE-2019-0604: Details of a Microsoft Sharepoint RCE Vulnerability (thezdi.com)
1 point by infosecau on March 23, 2019 | past
22.Discovering a zero day and getting code execution on Mozilla's AWS Network (assetnote.io)
4 points by infosecau on March 19, 2019 | past
23.Gaining access to Uber's user data through AMPScript evaluation (assetnote.io)
2 points by infosecau on Jan 14, 2019 | past
24.Leveraging web application vulnerabilities to steal NTLM hashes (blazeinfosec.com)
1 point by infosecau on Dec 24, 2017 | past
25.Commonspeak: Content discovery wordlists built with BigQuery (pentester.io)
1 point by infosecau on Dec 4, 2017 | past
26.Breach Detection at Scale with PROJECT SPACECRAB (atlassian.com)
1 point by infosecau on Oct 23, 2017 | past
27.Exploiting Dolphin – Part 1 (dougallj.wordpress.com)
1 point by infosecau on Nov 14, 2016 | past
28.Taking Over DigitalOcean Domains via a Lax Domain Import System (thehackerblog.com)
385 points by infosecau on Aug 26, 2016 | past | 170 comments
29.SmashBot – An AI That Plays Super Smash Bros (github.com/altf4)
1 point by infosecau on June 7, 2016 | past
30.Exploring the QNX shadowed password hash formats (moar.so)
3 points by infosecau on Dec 28, 2015 | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: