𝐞𝐧𝐞𝐬

283 posts

𝐞𝐧𝐞𝐬

𝐞𝐧𝐞𝐬

@EnesSaltk7

a.k.a phlmox | I’m something of a hacker myself

Katılım Haziran 2020
201 Takip Edilen583 Takipçiler
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
Insecure Message Listener -> DOM XSS -> Authorized access to API routes via CORS An attacker can extract users' critical information and modify it. An attacker can also make withdrawal requests on behalf of users. Their response? #bugbounty +++
𝐞𝐧𝐞𝐬 tweet media
English
2
3
42
3.1K
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
They continued to claim that this is neither critical nor even a real vulnerability, but merely social engineering. So I am disclosing it with their permission. The vulnerability is still there, but according to them, it does not pose any real problem at all.
English
0
0
5
436
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
"Based on our data, the team has not considered this vulnerability critical." You might ask why. I asked the same thing. Their reply was: "The vulnerability in question is a form of phishing."
𝐞𝐧𝐞𝐬 tweet media
English
1
0
4
325
𝐞𝐧𝐞𝐬 retweetledi
Jorian
Jorian@J0R1AN·
Here is my writeup of Intigriti's December XSS challenge. It consisted of 6 smaller challenges combining into a big 1-click exploit. One of the most fun ones I've ever played. Loved the unique format by @RenwaX23! jorianwoltjer.com/blog/p/ctf/int…
English
4
30
131
10.9K
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
third party account linking - account takeover TL;DR: The developers didn't use OAuth's state parameter or implement their own CSRF protection, which led to my OAuth account being linked to theirs. phlmox.medium.com/third-party-ac…
English
0
0
2
255
Rıza
Rıza@rizasabuncu·
ne tesadüf
Rıza tweet media
Türkçe
7
0
110
18K
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
Account takeover via insecure postMessage: @phlmox/account-takeover-via-postmessage-3c493c6d1354" target="_blank" rel="nofollow noopener">medium.com/@phlmox/accoun… nothing fancy, just wanted to write something #bugbounty
𝐞𝐧𝐞𝐬 tweet media
English
0
2
8
516
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
@sametsahinnet Great extension, I appreciate your work. However, it couldn't find the 'API_KEY' variable on the web page due to the carriage return characters in your watchlist.txt. It works fine when you remove them.
English
0
0
1
270
Samet Sahin
Samet Sahin@sametsahinnet·
I'm excited 🎉 to introduce collectvars! A browser extension that finds all JS variables and detects dangerous ones. So you can find secrets and earn money while casually browsing. Check it out github.com/sametsahinnet/… #BugBounty
English
2
30
137
9.6K
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
@buckberi 1500 ile başladık 30 ile kapatıyoruz :) ya da kapatmıyoruz 3 euro da olabilir her an
Türkçe
1
0
0
504
Recep Baltaş
Recep Baltaş@buckberi·
Bugün de güne 150 Euro olan yurt dışı sipariş limitinin 30 Euro’ya düşürüldüğü haberiyle başladık. 24 Ağustos'tan itibaren 30 Euro üstü gümrükten geçmeyecek.
Türkçe
94
49
1.7K
200.1K
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
This might be the most stupid bug ever: a 6-character long email verification code was leaked in response as an encrypted SHA1
𝐞𝐧𝐞𝐬 tweet media
English
0
0
1
317
𝐞𝐧𝐞𝐬
𝐞𝐧𝐞𝐬@EnesSaltk7·
Modified my JSLinkfinderv2 Burp suite extension which is clone of the original InitRoot's BurpJSLinkFinder and now it's available for community edition. github.com/phlmox/BurpJSL…
𝐞𝐧𝐞𝐬 tweet media𝐞𝐧𝐞𝐬 tweet media
English
1
10
72
5.3K
𝐞𝐧𝐞𝐬 retweetledi
Mustafa Can İPEKÇİ
Mustafa Can İPEKÇİ@mcipekci·
@Hacker0x01 @jobertabma @martenmickos As I know each year #hackforgood destination changes, first it was for COVID-19 then for supporting Ukraine. As you know one of biggest earthquakes recently happened in Türkiye, per this tweet more than 17K lost their lives.
English
10
24
99
20.2K
𝐞𝐧𝐞𝐬 retweetledi
Ali Tütüncü
Ali Tütüncü@alicanact60·
Two major earthquakes, measuring 7.7 and 7.5 hit Turkey 2 days ago. There are tens of thousands of people waiting for our help right now. If you want to help you can use it here: ahbap.org/disasters-turk… Every single Like & RT is appreciated.
English
5
50
117
33.2K