𝐞𝐧𝐞𝐬
283 posts

𝐞𝐧𝐞𝐬
@EnesSaltk7
a.k.a phlmox | I’m something of a hacker myself
Katılım Haziran 2020
201 Takip Edilen583 Takipçiler
𝐞𝐧𝐞𝐬 retweetledi

en buyuk cok buyuk ctf geliyor!!!!!
numan turle@numanturle
🚨🐱💻 TÜRKİYE'NİN EN BÜYÜK CTF'İ GELİYOR! 70 milyon kişi bekleniyor. En zor sorular bizde. Yapay zeka bile çözemiyor. Hacker kediler hazır, peki ya sen? 🔥 Kayıt ol: cokbuyukctf.com #EnBüyükCTF #CTF #SiberGüvenlik #HackerKedi 🐱 via - @divinepwner
Türkçe

Insecure Message Listener -> DOM XSS -> Authorized access to API routes via CORS
An attacker can extract users' critical information and modify it.
An attacker can also make withdrawal requests on behalf of users.
Their response? #bugbounty
+++

English

Bug bounty sırasında bulduğum ve Cloudflare WAF'ı bypassladığım RXSS yazısı.
phlmox.medium.com/tr-reflected-x…
Türkçe
𝐞𝐧𝐞𝐬 retweetledi

Here is my writeup of Intigriti's December XSS challenge. It consisted of 6 smaller challenges combining into a big 1-click exploit.
One of the most fun ones I've ever played. Loved the unique format by @RenwaX23!
jorianwoltjer.com/blog/p/ctf/int…
English

third party account linking - account takeover
TL;DR: The developers didn't use OAuth's state parameter or implement their own CSRF protection, which led to my OAuth account being linked to theirs.
phlmox.medium.com/third-party-ac…
English

If you find an HTML injection but can't escalate it to XSS due to blacklisted elements, try DOM Clobbering. portswigger.net/web-security/d…

English

Account takeover via insecure postMessage:
@phlmox/account-takeover-via-postmessage-3c493c6d1354" target="_blank" rel="nofollow noopener">medium.com/@phlmox/accoun…
nothing fancy, just wanted to write something
#bugbounty

English

@sametsahinnet Great extension, I appreciate your work. However, it couldn't find the 'API_KEY' variable on the web page due to the carriage return characters in your watchlist.txt. It works fine when you remove them.
English

I'm excited 🎉 to introduce collectvars!
A browser extension that finds all JS variables and detects dangerous ones.
So you can find secrets and earn money while casually browsing.
Check it out github.com/sametsahinnet/…
#BugBounty
English

Modified my JSLinkfinderv2 Burp suite extension which is clone of the original InitRoot's BurpJSLinkFinder and now it's available for community edition.
github.com/phlmox/BurpJSL…


English
𝐞𝐧𝐞𝐬 retweetledi

@Hacker0x01 @jobertabma @martenmickos As I know each year #hackforgood destination changes, first it was for COVID-19 then for supporting Ukraine.
As you know one of biggest earthquakes recently happened in Türkiye, per this tweet more than 17K lost their lives.
English
𝐞𝐧𝐞𝐬 retweetledi

Two major earthquakes, measuring 7.7 and 7.5 hit Turkey 2 days ago. There are tens of thousands of people waiting for our help right now. If you want to help you can use it here:
ahbap.org/disasters-turk…
Every single Like & RT is appreciated.
English







