#DNS #GoogleCloudPlatform Cloudflare setup to RDP server for 10 users: have a main office with a static IP, an RDP server and no website but have extr ...September 18, 2021
#infosec #informationsecurity How to hack and bypass a web application firewall WAF during penetrating testing https://t.co/6xSvF8TKQ6 https://t.co/Gf ...September 16, 2021
1. It's a "news" profile but refuses to cite the source of content;
2. It provides no context on why those payloads are that way;
3. It says "LFI" not ...September 15, 2021
Akamaighost waf prompt(/AAA/) bypass, while prompt(/XSS/) blocked, so developers decide to block the word XSS to prevent researchers from posting PoC ...September 15, 2021
Injection selalu masuk top ten OWASP.
Di indonesia, Masih banyak K/L yang berpikir bahwa dengan menggunakan WAF maka mereka aman dari injection khusu ...September 15, 2021
#EmailHandling #Linux Mailwizz Job -Setup tracking Domain on cloudflare and SSL: Looking for a competent mailwizz guy to setup a tracking domain and s ...September 13, 2021
Worried about EL and OGNL injection? They’re tricky to find and exploits can bypass your WAF. Contrast directly observes all expression evaluation ...September 10, 2021
#DNS #Linux Subdomain: Need help setting up a subdomain through CPanel and Cloudflare. I have followed all the steps but still getting DNS_PROBE_FINIS ...September 7, 2021
Bug bounty companies be like "We are not interested in bugs in things that aren't our products. Unless you can non-destructively prove RCE exists in o ...September 7, 2021
If you find #SSRF and got stuck with cloudflare go and take a look at my write up: "https://t.co/1AeGVINWwF" #cloudflarebypass #bypass #bugbountytips ...September 7, 2021
If you see a web application is trying to guess your search query (e.g. in search bar) and has a WAF on top of it, use mistyped words to easy trigger ...September 7, 2021
pFuzz is an advanced red teaming fuzzing tool which we developed for our research. It helps us to bypass web application firewall by using different m ...September 7, 2021
proving grounds - xposedapi
in this we gonna bypass waf with x-forwarded-for header and find a lfi vuln
and we send payload and /update it
after get ...September 7, 2021